Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-23686


DependencyCheck for Maven 9.0.0 to 9.0.6, for CLI version 9.0.0 to 9.0.5, and for Ant versions 9.0.0 to 9.0.5, when used in debug mode, allows an attacker to recover the NVD API Key from a log file.


Published

2024-01-19T22:15:08.437

Last Modified

2025-06-17T15:15:40.450

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.3 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-532
  • Type: Primary
    CWE-532

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application owasp dependency-check ≤ 9.0.5 Yes
Application owasp dependency-check ≤ 9.0.5 Yes
Application owasp dependency-check < 9.0.6 Yes

References