Updatecli is a tool used to apply file update strategies. Prior to version 0.93.0, private maven repository credentials may be leaked in application logs in case of unsuccessful retrieval operation. During the execution of an updatecli pipeline which contains a `maven` source configured with basic auth credentials, the credentials are being leaked in the application execution logs in case of failure. Credentials are properly sanitized when the operation is successful but not when for whatever reason there is a failure in the maven repository, e.g. wrong coordinates provided, not existing artifact or version. Version 0.93.0 contains a patch for the issue.
Metrics
Affected Vendors & Products
References
History
Wed, 12 Feb 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 24 Jan 2025 17:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Updatecli is a tool used to apply file update strategies. Prior to version 0.93.0, private maven repository credentials may be leaked in application logs in case of unsuccessful retrieval operation. During the execution of an updatecli pipeline which contains a `maven` source configured with basic auth credentials, the credentials are being leaked in the application execution logs in case of failure. Credentials are properly sanitized when the operation is successful but not when for whatever reason there is a failure in the maven repository, e.g. wrong coordinates provided, not existing artifact or version. Version 0.93.0 contains a patch for the issue. | |
Title | Updatecli may expose Maven credentials in console output | |
Weaknesses | CWE-359 | |
References |
| |
Metrics |
cvssV3_0
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-01-24T16:48:17.723Z
Updated: 2025-02-12T20:01:18.920Z
Reserved: 2025-01-20T15:18:26.988Z
Link: CVE-2025-24355

Updated: 2025-02-12T19:55:39.517Z

Status : Received
Published: 2025-01-24T17:15:16.047
Modified: 2025-01-24T17:15:16.047
Link: CVE-2025-24355

No data.