{"id":"GHSA-qqhq-8r2c-c3f5","summary":"nvdApiKey is logged in debug mode","details":"### Summary\nThe value of `nvdApiKey` configuration parameter is logged in clear text in debug mode.\n\n### Details\nThe NVD API key is a kind of secret and should be treated like other secrets when logging in debug mode.\nExpecting the same behavior as for several password configurations: just print `******`\n\nNote that while the NVD API Key is an access token for the NVD API - they are not that sensitive. The only thing an NVD API Token grants is a higher rate limit when making calls to publicly available data. The data available from the NVD API is the same whether you have an API Key or not.\n\n### PoC\nThe nvdApiKey is configured to use an environment variable; when running `mvn -X dependency-check:check` the clear value is logged twice.\n\n### Impact\nThe NVD API key is a kind of secret and should not be exposed. If stolen, an attacker can use this key to obtain already public information.\n\n","aliases":["CVE-2024-23686","GHSA-frxm-v7q3-v2wv"],"modified":"2026-05-06T12:44:53.549414315Z","published":"2023-12-15T23:43:30Z","database_specific":{"cwe_ids":["CWE-532"],"severity":"LOW","github_reviewed":true,"github_reviewed_at":"2023-12-15T23:43:30Z","nvd_published_at":null},"references":[{"type":"WEB","url":"https://github.com/jeremylong/DependencyCheck/security/advisories/GHSA-qqhq-8r2c-c3f5"},{"type":"PACKAGE","url":"https://github.com/jeremylong/DependencyCheck"}],"affected":[{"package":{"name":"org.owasp:dependency-check-ant","ecosystem":"Maven","purl":"pkg:maven/org.owasp/dependency-check-ant"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"9.0.0"},{"fixed":"9.0.6"}]}],"versions":["9.0.0","9.0.1","9.0.2","9.0.3","9.0.4","9.0.5"],"database_specific":{"last_known_affected_version_range":"\u003c= 9.0.5","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/12/GHSA-qqhq-8r2c-c3f5/GHSA-qqhq-8r2c-c3f5.json"}},{"package":{"name":"org.owasp:dependency-check-cli","ecosystem":"Maven","purl":"pkg:maven/org.owasp/dependency-check-cli"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"9.0.0"},{"fixed":"9.0.6"}]}],"versions":["9.0.0","9.0.1","9.0.2","9.0.3","9.0.4","9.0.5"],"database_specific":{"last_known_affected_version_range":"\u003c= 9.0.5","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/12/GHSA-qqhq-8r2c-c3f5/GHSA-qqhq-8r2c-c3f5.json"}},{"package":{"name":"org.owasp:dependency-check-maven","ecosystem":"Maven","purl":"pkg:maven/org.owasp/dependency-check-maven"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"9.0.0"},{"fixed":"9.0.6"}]}],"versions":["9.0.0","9.0.1","9.0.2","9.0.3","9.0.4","9.0.5"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/12/GHSA-qqhq-8r2c-c3f5/GHSA-qqhq-8r2c-c3f5.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"}]}