CVE-2023-40626: [20231101] - Core - Exposure of environment variables
Published Nov 29, 2023
·Updated
The language file parsing process could be manipulated to expose environment variables. Environment variables might contain sensible information.
Affected Software
3 affected components
Joomla Joomla\!>=1.6.0<3.10.14
Joomla Joomla\!>=4.0.0<4.4.1
Joomla Joomla\!=5.0.0
Event History
Nov 29, 2023
CVE Published
12:28 PM
Data Sourced
12:28 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this exposure of environment variables?
The vulnerability ID for this exposure of environment variables is CVE-2023-40626.
2
What is the severity of CVE-2023-40626?
The severity of CVE-2023-40626 is high with a severity value of 7.5.
3
Which versions of Joomla are affected by CVE-2023-40626?
Joomla versions 1.6.0 to 3.10.14, Joomla versions 4.0.0 to 4.4.1, and Joomla version 5.0.0 are affected by CVE-2023-40626.
4
What is the risk associated with this vulnerability?
The risk associated with this vulnerability is the exposure of sensitive information stored in environment variables.
5
Is there a fix available for CVE-2023-40626?
Yes, a fix for CVE-2023-40626 is available. Please refer to the reference link for more details.