CVE Vulnerabilities

CVE-2023-40626

Published: Nov 29, 2023 | Modified: Dec 05, 2023
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

The language file parsing process could be manipulated to expose environment variables. Environment variables might contain sensible information.

Affected Software

Name Vendor Start Version End Version
Joomla! Joomla 1.6.0 (including) 3.10.14 (excluding)
Joomla! Joomla 4.0.0 (including) 4.4.1 (excluding)
Joomla! Joomla 5.0.0 (including) 5.0.0 (including)

References