Plaintext Password Storage in Janssen Identity and Access Management Platform
CVE-2025-54876
6.9MEDIUM
What is CVE-2025-54876?
The Janssen Project's open-source IAM platform has a significant vulnerability where passwords are stored in plaintext within the local cli_cmd.log file. This creates a severe risk of unauthorized access, as sensitive information is easily retrievable by anyone with access to the log file. The issue was present in versions up to 1.9.0 and has been addressed in the latest nightly prerelease. It's crucial for users of the Janssen platform to update to the latest version to secure their sensitive data.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
jans < nightly
References
CVSS V4
Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
