CVE-2025-54876

The Janssen Project is an open-source identity and access management (IAM) platform. In versions 1.9.0 and below, Janssen stores passwords in plaintext in the local cli_cmd.log file. This is fixed in the nightly prerelease.
CVSS

No CVSS.

Configurations

No configuration.

History

23 Jan 2026, 18:16

Type Values Removed Values Added
References
  • {'url': 'https://github.com/JanssenProject/jans/pull/11903/commits/5260520e8d7ce1d1b8387c71b3571f20e643f110', 'source': 'security-advisories@github.com'}
  • () https://github.com/JanssenProject/jans/commit/3592837764fe48b956e3140ca17b8ef7cac00a47 -
  • () https://github.com/JanssenProject/jans/pull/11903 -

06 Aug 2025, 20:23

Type Values Removed Values Added
Summary
  • (es) Janssen Project es una plataforma de gestión de identidades y accesos (IAM) de código abierto. En las versiones 1.9.0 y anteriores, Janssen almacena las contraseñas en texto plano en el archivo local cli_cmd.log. Esto se solucionó en la versión preliminar nocturna.

06 Aug 2025, 00:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-06 00:15

Updated : 2026-04-15 00:35


NVD link : CVE-2025-54876

Mitre link : CVE-2025-54876

CVE.ORG link : CVE-2025-54876


JSON object : View

Products Affected

No product.

CWE
CWE-522

Insufficiently Protected Credentials