Updatecli Private Maven Repository Credential Leak Vulnerability
Vulnerability
A vulnerability in Updatecli prior to version 0.93.0 allows private Maven repository credentials to be leaked in application logs during unsuccessful retrieval operations. When an Updatecli pipeline includes a Maven source with basic authentication credentials, these credentials are exposed in the execution logs if the operation fails, such as due to incorrect coordinates or a non-existent artifact or version. In contrast, credentials are properly sanitized when the operation is successful.
Impact
This vulnerability can lead to the unintentional exposure of user credentials or tokens used to authenticate with private Maven repositories, allowing for potential misuse of these credentials.
Reproduction
To reproduce this vulnerability, configure an Updatecli pipeline with a Maven source that includes basic authentication credentials in the repository field. Then, specify a non-existent artifact or version. The application logs will reveal the unredacted credentials, demonstrating the leak.
Remediation
Updatecli users should upgrade to version 0.93.0 or later, where this vulnerability has been patched.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
