CVE Vulnerabilities

CVE-2023-40626

Published: Nov 29, 2023 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The language file parsing process could be manipulated to expose environment variables. Environment variables might contain sensible information.

Affected Software

NameVendorStart VersionEnd Version
Joomla!Joomla1.6.0 (including)3.10.14 (excluding)
Joomla!Joomla4.0.0 (including)4.4.1 (excluding)
Joomla!Joomla5.0.0 (including)5.0.0 (including)

References