CVE-2022-31185

Source
https://nvd.nist.gov/vuln/detail/CVE-2022-31185
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-31185.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-31185
Aliases
  • GHSA-jm39-h693-678g
Published
2022-08-01T19:25:11Z
Modified
2025-11-04T20:02:22.637559Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
Email addresses are not hidden regardless of selected state in mprweb
Details

mprweb is a hosting platform for the makedeb Package Repository. Email addresses were found to not have been hidden, even if a user had clicked the Hide Email Address checkbox on their account page, or during signup. This could lead to an account's email being leaked, which may be problematic if your email needs to remain private for any reason. Users hosting their own mprweb instance will need to upgrade to the latest commit to get this fixed. Users on the official instance will already have this issue fixed.

Database specific
{
    "cwe_ids": [
        "CWE-200"
    ]
}
References

Affected packages

Git / github.com/makedeb/mprweb

Affected ranges

Type
GIT
Repo
https://github.com/makedeb/mprweb
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

1.*

1.0
1.0.1
1.0.2
1.0.3
1.1
1.2.10
1.2.8
1.2.9
1.3.0
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.6.1
1.5.6.2
1.5.6.3
1.5.6.4
1.6.0
1.7.0
1.8.0
1.8.1
1.8.2

v1.*

v1.9.0
v1.9.1

v2.*

v2.0.0
v2.0.0-rc1
v2.0.0-rc2
v2.0.1
v2.1.0
v2.2.0
v2.2.1
v2.3.0

v3.*

v3.0.0
v3.0.0-rc1
v3.0.0-rc2
v3.0.0-rc3
v3.0.0-rc4
v3.1.0
v3.2.0
v3.3.0
v3.4.0
v3.4.1
v3.4.2
v3.4.3
v3.5.0
v3.5.1

v4.*

v4.0.0
v4.0.0-rc1
v4.0.0-rc2
v4.0.0-rc3
v4.0.0-rc4
v4.0.0-rc5
v4.0.0-rc6
v4.1.0
v4.1.1
v4.2.0
v4.2.1
v4.3.0
v4.4.0
v4.4.1
v4.5.0
v4.5.1
v4.6.0
v4.7.0
v4.8.0

v5.*

v5.0.0