Insufficiently Protected Credentials
CVE-2025-54467
Summary
When a Java command with password parameters is executed and terminated by NeuVector for Process rule violation. For example, "java -cp /app ... Djavax.net.ssl.trustStorePassword=<Password>" The command with the password appears in the NeuVector security event. To prevent this, NeuVector uses the following default regular expression to detect and redact sensitive data from process commands. This vulnerability exists in versions 5.0.0 through 5.4.5
- LOW
- ADJACENT NETWORK
- NONE
- UNCHANGED
- NONE
- NONE
- LOW
- NONE
CWE-522 - Insufficiently Protected Credentials
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
References
Advisory Timeline
- Published