CVE-2025-54876 is a medium-severity vulnerability affecting Janssen Project versions 1.9.0 and below, where the IAM platform stores passwords in plaintext within the local cli_cmd.log file. This flaw, categorized as CWE-522, could lead to unauthorized disclosure of sensitive credentials if an attacker gains access to the log file. The CVSS 4.0 score of 6.9 indicates a network-exploitable vulnerability with low attack complexity, though the impact is limited to confidentiality. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion, and it is not listed in the CISA KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| JanssenProject | Jans | < nightlyCNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.