GHSA-q3hq-hm5h-qrx3, CVE-2022-43691
packagist/concrete5/concrete5
Cleartext Transmission of Sensitive Information
Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 inadvertently disclose server-side sensitive information (secrets in environment variables and server information) when Debug Mode is left on in production.
All versions before 8.5.10, all versions starting from 9.0.0 before 9.1.3
Upgrade to versions 8.5.10, 9.1.3 or above.
2022-11-22
source |