MEDIUM
Jans CLI stores plaintext passwords in the local cli_cmd.log file
Published Aug 5, 2025
6.9
MEDIUMCVSS 4.0
EPSS 0.48%
Description
The Janssen Project is an open-source identity and access management (IAM) platform. In versions 1.9.0 and below, Janssen stores passwords in plaintext in the local cli_cmd.log file. This is fixed in the nightly prerelease.
Affected products
-
- Version < nightlyStatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| JanssenProject | Jans | n/a |
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- https://github.com/JanssenProject/jans/commit/3592837764fe48b956e3140ca17b8ef7cac00a47 x_refsource_MISC
- https://github.com/JanssenProject/jans/discussions/11886 x_refsource_MISC
- https://github.com/JanssenProject/jans/pull/11903 x_refsource_MISC
- https://github.com/JanssenProject/jans/security/advisories/GHSA-2f4x-m695-jvp3 x_refsource_CONFIRM
| Link | Providers | Tags |
|---|---|---|
| https://github.com/JanssenProject/jans/commit/3592837764fe48b956e3140ca17b8ef7cac00a47 | x_refsource_MISC | |
| https://github.com/JanssenProject/jans/discussions/11886 | x_refsource_MISC | |
| https://github.com/JanssenProject/jans/pull/11903 | x_refsource_MISC | |
| https://github.com/JanssenProject/jans/security/advisories/GHSA-2f4x-m695-jvp3 | x_refsource_CONFIRM |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Aug 5, 2025
Updated Jan 23, 2026
Reserved Jul 31, 2025
Link CVE-2025-54876
CISA Vulnrichment
Updated Aug 6, 2025