CVE-2023-47639

Source
https://nvd.nist.gov/vuln/detail/CVE-2023-47639
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-47639.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-47639
Aliases
Published
2025-04-03T16:46:13.632Z
Modified
2025-12-05T00:10:33.124335Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
API Platform Core can leak exceptions message that may contain sensitive information
Details

API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. From 3.2.0 until 3.2.4, exception messages, that are not HTTP exceptions, are visible in the JSON error response. This vulnerability is fixed in 3.2.5.

Database specific
{
    "cna_assigner": "GitHub_M",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/47xxx/CVE-2023-47639.json",
    "cwe_ids": [
        "CWE-209"
    ]
}
References

Affected packages

Git / github.com/api-platform/core

Affected ranges

Type
GIT
Repo
https://github.com/api-platform/core
Events

Affected versions

v3.*

v3.1.21
v3.1.22
v3.2.0
v3.2.1
v3.2.2
v3.2.3
v3.2.4