QID 996846

Date Published: 2024-01-24

QID 996846: Java (Maven) Security Update for org.owasp:dependency-check-ant (GHSA-frxm-v7q3-v2wv)

DependencyCheck for Maven 9.0.0 to 9.0.6, for CLI version 9.0.0 to 9.0.5, and for Ant versions 9.0.0 to 9.0.5, when used in debug mode, allows an attacker to recover the NVD API Key from a log file.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Medium - 5.3 severity.
  • CVSS V2 rated as Medium - 5.4 severity.
  • Solution
    Refer to Github security advisory GHSA-frxm-v7q3-v2wv for updates and patch information.
    Vendor References

    CVEs related to QID 996846

    Software Advisories
    Advisory ID Software Component Link
    GHSA-frxm-v7q3-v2wv org.owasp:dependency-check-ant URL Logo github.com/advisories/GHSA-frxm-v7q3-v2wv