CVE-2025-54876 Information

Description

The Janssen Project is an open-source identity and access management (IAM) platform. In versions 1.9.0 and below Janssen stores passwords in plaintext in the local cli_cmd.log file. This is fixed in the nightly prerelease.

Reference

https://github.com/JanssenProject/jans/discussions/11886 https://github.com/JanssenProject/jans/pull/11903/commits/5260520e8d7ce1d1b8387c71b3571f20e643f110 https://github.com/JanssenProject/jans/security/advisories/GHSA-2f4x-m695-jvp3

CNNVD-202508-424 (Published: 2025-08-06)

Share on: