SCA: security update for github.com/updatecli/updatecli (GHSA-v34r-vj4r-38j6)

high Tenable Cloud Security Plugin ID 420769

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Updatecli is a tool used to apply file update strategies. Prior to version 0.93.0, private maven
repository credentials may be leaked in application logs in case of unsuccessful retrieval operation.
During the execution of an updatecli pipeline which contains a `maven` source configured with basic auth
credentials, the credentials are being leaked in the application execution logs in case of failure.
Credentials are properly sanitized when the operation is successful but not when for whatever reason there
is a failure in the maven repository, e.g. wrong coordinates provided, not existing artifact or version.
Version 0.93.0 contains a patch for the issue. (CVE-2025-24355)

See Also

https://github.com/advisories/GHSA-v34r-vj4r-38j6

Plugin Details

Severity: High

ID: 420769

Version: Revision 1.8

Type: Local

Family: SCA Checks

Published: 1/25/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3.3

Percentile: 51.27

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: Medium

Base Score: 4.9

Temporal Score: 3.6

Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:N/A:N

CVSS Score Source: CVE-2025-24355

CVSS v3

Risk Factor: High

Base Score: 7.1

Temporal Score: 6.2

Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 1/24/2025

Vulnerability Publication Date: 1/24/2025

Reference Information

CVE: CVE-2025-24355

cwe: CWE-359