First published: Wed Nov 29 2023(Updated: )
The language file parsing process could be manipulated to expose environment variables. Environment variables might contain sensible information.
Credit: security@joomla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Joomla Joomla\! | >=1.6.0<3.10.14 | |
Joomla Joomla\! | >=4.0.0<4.4.1 | |
Joomla Joomla\! | =5.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this exposure of environment variables is CVE-2023-40626.
The severity of CVE-2023-40626 is high with a severity value of 7.5.
Joomla versions 1.6.0 to 3.10.14, Joomla versions 4.0.0 to 4.4.1, and Joomla version 5.0.0 are affected by CVE-2023-40626.
The risk associated with this vulnerability is the exposure of sensitive information stored in environment variables.
Yes, a fix for CVE-2023-40626 is available. Please refer to the reference link for more details.