DependencyCheck Debug Mode Logging of NVD API Key
Summary
| CVE | CVE-2024-23686 |
|---|---|
| State | PUBLISHED |
| Assigner | VulnCheck |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2024-01-19 22:15:08 UTC |
| Updated | 2026-07-14 23:17:16 UTC |
| Description | DependencyCheck for Maven 9.0.0 to 9.0.6, for CLI version 9.0.0 to 9.0.5, and for Ant versions 9.0.0 to 9.0.5, when used in debug mode, allows an attacker to recover the NVD API Key from a log file. |
Risk And Classification
Primary CVSS: v3.1 5.3 MEDIUM from [email protected]
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS: 0.005980000 probability, percentile 0.446490000 (date 2026-07-16)
Problem Types: CWE-532 | CWE-532 CWE-532 Insertion of Sensitive Information into Log File
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 5.3 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
| 3.1 | ADP | DECLARED | 5.3 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
| 3.1 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | Secondary | 5.3 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
LowIntegrity
NoneAvailability
NoneCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Owasp | Dependency-check | All | All | All | All |
| Application | Owasp | Dependency-check | All | All | All | All |
| Application | Owasp | Dependency-check | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| vulncheck.com/advisories/vc-advisory-GHSA-qqhq-8r2c-c3f5 | af854a3a-2127-422b-91ae-364da2661108 | vulncheck.com | Third Party Advisory |
| nvdApiKey is logged in debug mode · Advisory · jeremylong/DependencyCheck · GitHub | af854a3a-2127-422b-91ae-364da2661108 | github.com | Vendor Advisory |
| github.com/advisories/GHSA-qqhq-8r2c-c3f5 | af854a3a-2127-422b-91ae-364da2661108 | github.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 996846 Java (Maven) Security Update for org.owasp:dependency-check-ant (GHSA-frxm-v7q3-v2wv)