PMD is an extensible multilanguage static code analyzer. The passphrase for the PMD and PMD Designer release signing keys are included in jar published to Maven Central. The private key itself is not known to have been compromised itself, but given its passphrase is, it must also be considered potentially compromised. As a mitigation, both compromised keys have been revoked so that no future use of the keys are possible. Note, that the published artifacts in Maven Central under the group id net.sourceforge.pmd are not compromised and the signatures are valid.
History

Fri, 31 Jan 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 31 Jan 2025 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-312

Fri, 31 Jan 2025 15:30:00 +0000

Type Values Removed Values Added
Description PMD is an extensible multilanguage static code analyzer. The passphrase for the PMD and PMD Designer release signing keys are included in jar published to Maven Central. The private key itself is not known to have been compromised itself, but given its passphrase is, it must also be considered potentially compromised. As a mitigation, both compromised keys have been revoked so that no future use of the keys are possible. Note, that the published artifacts in Maven Central under the group id net.sourceforge.pmd are not compromised and the signatures are valid.
Title PMD Designer's release key passphrase (GPG) available on Maven Central in cleartext
Weaknesses CWE-200
CWE-540
References
Metrics cvssV4_0

{'score': 0, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/MVC:N/MVI:N/MVA:N/U:Clear'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-01-31T16:49:52.616Z

Reserved: 2025-01-13T17:15:41.051Z

Link: CVE-2025-23215

cve-icon Vulnrichment

Updated: 2025-01-31T16:49:28.848Z

cve-icon NVD

Status : Received

Published: 2025-01-31T16:15:35.643

Modified: 2025-01-31T17:15:16.957

Link: CVE-2025-23215

cve-icon Redhat

No data.