Lucene search

K
cve[email protected]CVE-2022-39351
HistoryOct 25, 2022 - 5:15 p.m.

CVE-2022-39351

2022-10-2517:15:56
CWE-312
web.nvd.nist.gov
33
7
cve-2022-39351
dependency-track
component analysis platform
software supply chain
api key
unauthorized access
security flaw

4.4 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

4.8 Medium

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

17.2%

Dependency-Track is a Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain. Prior to version 4.6.0, performing an API request using a valid API key with insufficient permissions causes the API key to be written to Dependency-Track’s audit log in clear text. Actors with access to the audit log can exploit this flaw to gain access to valid API keys. The issue has been fixed in Dependency-Track 4.6.0. Instead of logging the entire API key, only the last 4 characters of the key will be logged. It is strongly recommended to check historic logs for occurrences of this behavior, and re-generating API keys in case of leakage.

Affected configurations

Vulners
NVD
Node
dependencytrackdependency_trackRange<4.6.0

CNA Affected

[
  {
    "vendor": "DependencyTrack",
    "product": "dependency-track",
    "versions": [
      {
        "version": "< 4.6.0",
        "status": "affected"
      }
    ]
  }
]

Social References

More

4.4 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

4.8 Medium

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

17.2%

Related for CVE-2022-39351