Skip to main content

Insufficiently Protected Credentials

CVE-2025-54467

Severity Medium
Score 4.3/10

Summary

When a Java command with password parameters is executed and terminated by NeuVector for Process rule violation. For example, "java -cp /app ... Djavax.net.ssl.trustStorePassword=<Password>" The command with the password appears in the NeuVector security event. To prevent this, NeuVector uses the following default regular expression to detect and redact sensitive data from process commands. This vulnerability exists in versions 5.0.0 through 5.4.5

  • LOW
  • ADJACENT NETWORK
  • NONE
  • UNCHANGED
  • NONE
  • NONE
  • LOW
  • NONE

CWE-522 - Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Advisory Timeline

  • Published