CVE-2025-23215 concerns PMD, an extensible static code analyzer, where the passphrases for its release signing keys were inadvertently included in JARs published to Maven Central. While the private keys themselves are not confirmed compromised, their exposed passphrases necessitate treating them as such. This vulnerability carries a critical CVSS score of 9.3 due to the potential for high impact on confidentiality, integrity, and availability, stemming from an unauthenticated network attack with low complexity. Both compromised keys have been revoked as a mitigation, and existing artifacts on Maven Central are not affected. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Pmd | Pmd | < 7.10.0CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Clear
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.