Lucene search

K
githubGitHub Advisory DatabaseGHSA-HWXF-QXJ7-7RFJ
HistoryOct 30, 2023 - 3:18 p.m.

CodeIgniter4 vulnerable to information disclosure when detailed error report is displayed in production environment

2023-10-3015:18:56
CWE-209
GitHub Advisory Database
github.com
31
codeigniter4
vulnerability
information disclosure
production environment
upgrade
detailed error report
confidential information
patch
workaround
security advisory

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

6.8 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

28.1%

Impact

If an error or exception occurs in CodeIgniter4 v4.4.2 and earlier, a detailed error report is displayed even if in the production environment. As a result, confidential information may be leaked.

Patches

Upgrade to v4.4.3 or later. See upgrading guide.

Workarounds

Replace ini_set('display_errors', '0') with ini_set('display_errors', 'Off') in app/Config/Boot/production.php.

For more information

If you have any questions or comments about this advisory:

Affected configurations

Vulners
Node
codeigniter4frameworkRange4.4.2
CPENameOperatorVersion
codeigniter4/frameworkle4.4.2

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

6.8 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

28.1%

Related for GHSA-HWXF-QXJ7-7RFJ