Impact
The vulnerability allows an actor with read access to Renovate logs to retrieve TLS private keys that are used for mutual authentication. The implementation flaw results in incomplete redaction of the hostRules[].httpsPrivateKey value when it is referenced elsewhere in configuration or log messages, leaving the full key in plaintext. The exposed key could be used to impersonate the service, gain unauthorized access, or compromise future connections. This flaw is a classic example of log injection and improper sanitisation, corresponding to CWE-532.
Affected Systems
The affected product is Renovate, the automated dependency update tool produced by renovatebot. Versions earlier than 44.14.4 are impacted, as are Mend‑Renovate CE/EE Docker images below version 15.4.0 and the mend-renovate‑enterprise‑edition Helm chart prior to 10.4.0. Any deployment that configures the httpsPrivateKey in hostRules[].httpsPrivateKey without delivering it through the documented secrets configuration is vulnerable.
Risk and Exploitability
The CVSS score of 8.3 indicates a high impact. The EPSS score of 0.28 % shows a very low probability of exploitation in the wild and the vulnerability is not listed in CISA’s KEV catalog, suggesting no confirmed widespread exploitation. The attack requires read access to the Renovate logs; an attacker who can read these logs could extract the TLS private key and use it to impersonate the service or establish unauthorized TLS connections. Therefore, while the technical impact is severe, the likelihood of exploitation is currently very low but patching remains recommended.
OpenCVE Enrichment