PT-2025-41166 · Unknown+1 · Dependency-Track+1

Colinfyfe

·

Published

2025-10-07

·

Updated

2025-10-07

·

CVE-2025-61776

CVSS v3.1

4.7

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Dependency-Track versions prior to 4.13.5
Description Dependency-Track is a component analysis platform used for managing software supply chain risk. Versions prior to 4.13.5 may inadvertently transmit credentials intended for a private NuGet repository to api.nuget.org through the HTTP Authorization header. This can also result in the disclosure of names and versions of internally marked components to api.nuget.org. This occurs when a Dependency-Track instance includes .NET components, a custom NuGet repository is configured, the repository is configured with authentication credentials, and the repository server does not provide the PackageBaseAddress resource in its service index.
Recommendations Disable custom NuGet repositories until version 4.13.5 is applied. Invalidate previously used credentials. Generate new credentials for use after applying version 4.13.5.

Exploit

Fix

Insufficiently Protected Credentials

Weakness Enumeration

Related Identifiers

CVE-2025-61776
GHSA-83G2-VGQH-MGXC

Affected Products

Dependency-Track
Nuget