blob: 2feb80d282c2acb4e8f7ba959ba74fd671ee1db0 [file] [log] [blame]
id: GO-2025-3419
modules:
- module: github.com/updatecli/updatecli
versions:
- fixed: 0.93.0
vulnerable_at: 0.92.0
summary: Updatecli exposes Maven credentials in console output in github.com/updatecli/updatecli
cves:
- CVE-2025-24355
ghsas:
- GHSA-v34r-vj4r-38j6
references:
- advisory: https://github.com/updatecli/updatecli/security/advisories/GHSA-v34r-vj4r-38j6
- advisory: https://nvd.nist.gov/vuln/detail/CVE-2025-24355
- fix: https://github.com/updatecli/updatecli/commit/344b28091ffeca5ed32e8d0f9eda542842fcd3fa
- web: https://www.updatecli.io/docs/plugins/resource/maven
source:
id: GHSA-v34r-vj4r-38j6
created: 2025-01-27T09:13:05.676114-05:00
review_status: UNREVIEWED