Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-ppm5-jv84-2xg2: Aimeos HTML client may potentially reveal sensitive information in error log

Impact

Debug information can reveal sensitive information from environment variables in error log

Affected platform

Laravel environments with multi-vendor setups and admin access for the vendors

ghsa
#git
  1. GitHub Advisory Database
  2. GitHub Reviewed
  3. CVE-2024-38516

Aimeos HTML client may potentially reveal sensitive information in error log

High severity GitHub Reviewed Published Jun 25, 2024 in aimeos/ai-client-html • Updated Jun 25, 2024

Package

composer aimeos/ai-client-html (Composer)

Affected versions

>= 2024.04.1, < 2024.04.7

>= 2023.04.1, < 2023.10.15

>= 2022.04.1, < 2022.10.13

>= 2021.10.1, < 2021.10.22

Patched versions

2024.04.7

2023.10.15

2022.10.13

2021.10.22

Impact

Debug information can reveal sensitive information from environment variables in error log

Affected platform

Laravel environments with multi-vendor setups and admin access for the vendors

References

  • GHSA-ppm5-jv84-2xg2
  • aimeos/ai-client-html@bb38962

Published to the GitHub Advisory Database

Jun 25, 2024

Last updated

Jun 25, 2024

ghsa: Latest News

GHSA-mj5r-x73q-fjw6: SPEmailHandler-PHP has Potential Abuse for Sending Arbitrary Emails