CVE-2023-46240
CVSS V2 None
CVSS V3 None
Description
CodeIgniter is a PHP full-stack web framework. Prior to CodeIgniter4 version 4.4.3, if an error or exception occurs, a detailed error report is displayed even if in the production environment. As a result, confidential information may be leaked. Version 4.4.3 contains a patch. As a workaround, replace `ini_set('display_errors', '0')` with `ini_set('display_errors', 'Off')` in `app/Config/Boot/production.php`.
Overview
- CVE ID
- CVE-2023-46240
- Assigner
- GitHub_M
- Vulnerability Status
- PUBLISHED
- Published Version
- 2023-10-31T15:03:51.798Z
- Last Modified Date
- 2023-10-31T15:03:51.798Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://github.com/codeigniter4/CodeIgniter4/security/advisories/GHSA-hwxf-qxj7-7rfj | x_refsource_CONFIRM |
https://github.com/codeigniter4/CodeIgniter4/commit/423569fc31e29f51635a2e59c89770333f0e7563 | x_refsource_MISC |
https://codeigniter4.github.io/userguide/general/errors.html#error-reporting | x_refsource_MISC |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2023-46240 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-46240 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-06-24 22:39:22 | Added to TrackCVE |