CVE-2023-40626

HIGH7.5EPSS 0.03%

[20231101] - Core - Exposure of environment variables

Published: 4/3/2025Modified: 5/20/2025

Description

The language file parsing process could be manipulated to expose environment variables. Environment variables might contain sensible information.

Affected packages (1)

  • Bitnami/joomla>= 1.6.0, < 3.10.14, >= 4.0.0, < 4.4.1 | >= 5.0.0, <= 5.0.0

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

References (2)