{"id":"CVE-2025-48955","summary":"Para Server Logs Sensitive Information","details":"Para is a multitenant backend server/framework for object persistence and retrieval. A vulnerability that exists in versions prior to 1.50.8 exposes both access and secret keys in logs without redaction. These credentials are later reused in variable assignments for persistence but do not require logging for debugging or system health purposes. Version 1.50.8 fixes the issue.","aliases":["GHSA-v75g-77vf-6jjq"],"modified":"2026-08-12T15:16:34.727845Z","published":"2025-06-02T11:11:22.722Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-532"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/48xxx/CVE-2025-48955.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/48xxx/CVE-2025-48955.json"},{"type":"ADVISORY","url":"https://github.com/Erudika/para/security/advisories/GHSA-v75g-77vf-6jjq"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-48955"},{"type":"FIX","url":"https://github.com/Erudika/para/commit/1e8a89558542854bb0683ab234c4429ad93b0835"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/erudika/para","events":[{"introduced":"0"},{"fixed":"1e8a89558542854bb0683ab234c4429ad93b0835"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"1.50.8"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["v1.50.7","v1.50.6","v1.50.5","v1.50.4","v1.50.3","v1.50.2","v1.50.1","v1.50.0","v1.49.5","v1.49.4","v1.49.3","v","v1.49.2","v1.49.1","v1.49.0","v1.48.2","v1.48.1","v1.48.0","v1.47.2","v1.47.1","v1.47.0","v1.46.3","v1.46.2","v1.46.1","v1.46.0","v1.45.10","v1.45.9","v1.45.8","v1.45.7","v1.45.6","v1.45.5","v1.45.4","v1.45.3","v1.45.2","v1.45.1","v1.45.0","v1.44.0","v1.43.4","v1.43.3","v1.43.2","v1.43.1","v1.43.0","v1.42.2","v1.42.1","v1.42.0","v1.41.3","v1.41.2","v1.41.1","v1.41.0","v1.40.0","v1.39.1","v1.39.0","v1.38.4","v1.38.3","v1.38.2","v1.38.1","v1.38.0","v1.37.1","v1.37.0","v1.36.1","v1.36.0","v1.35.0","v1.34.3","v1.34.2","v1.34.1","v1.34.0","v1.33.1","v1.33.0","v1.32.0","v1.31.3","v1.31.2","v1.31.1","v1.31.0","v1.30.2","v1.30.1","v1.30.0","v1.29.2","v1.29.1","v1.29.0","v1.28.5","v1.28.4","v1.28.3","v1.28.2","v1.28.1","v1.28.0","v1.27.0","v1.26.2","v1.26.1","v1.26.0","v1.25.5","v1.25.4","v1.25.3","v1.25.2","v1.25.1","v1.25.0","v1.24.5","v1.24.4","v1.24.3","v1.24.2","v1.24.1","v1.24.0","v1.23.1","v1.23.0","v1.22.0","v1.21.1","v1.21.0","v1.20.0","v1.19.0","v1.18.9","v1.18.8","v1.18.7","v1.18.6","v1.18.5","v1.18.4","v1.18.3","v1.18.2","v1.18.1","v1.18.0","v1.17.1","v1.17","v1.16.2","v1.16.1","v1.16","v1.15","v1.14.1","v1.14","v1.13","v1.12","v1.11","v1.10","v1.9.1","v1.9.0","v1.8.0","v1.7.0","v1.6.1","v1.6.0","v1.5.1","v1.5.0","v1.4.0","v1.3.1","v1.3.0","v1.2.1","v1.1.3","v1.1.2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-48955.json","vanir_signatures_modified":"2026-08-12T15:16:34Z","vanir_signatures":[{"deprecated":false,"digest":{"function_hash":"201706866908544889285737345888248064762","length":1234},"id":"CVE-2025-48955-3be0e4ba","signature_type":"Function","signature_version":"v1","source":"https://github.com/erudika/para/commit/1e8a89558542854bb0683ab234c4429ad93b0835","target":{"file":"para-server/src/main/java/com/erudika/para/server/utils/HealthUtils.java","function":"saveConfigFile"}},{"digest":{"threshold":0.9,"line_hashes":["258637137390929625815640386152755386172","28585999805322745124936474426664431949","255915147683167459992753520870456310741","247651089826939593266048593713131891810","275208719051312876599622191684594390216","239658961215119248594347050964618704546"]},"id":"CVE-2025-48955-48b286e3","signature_type":"Line","signature_version":"v1","source":"https://github.com/erudika/para/commit/1e8a89558542854bb0683ab234c4429ad93b0835","target":{"file":"para-server/src/main/java/com/erudika/para/server/utils/HealthUtils.java"},"deprecated":false}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}