CVE-2024-38516

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-38516
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-38516.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-38516
Aliases
Published
2024-06-25T20:08:50Z
Modified
2025-10-22T18:42:52.312235Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Aimeos HTML client may potentially reveal sensitive information in error log
Details

ai-client-html is an Aimeos e-commerce HTML client component. Debug information revealed sensitive information from environment variables in error log. This issue has been patched in versions 2024.04.7, 2023.10.15, 2022.10.13 and 2021.10.22.

Database specific
{
    "cwe_ids": [
        "CWE-1295"
    ]
}
References

Affected packages

Git / github.com/aimeos/ai-client-html

Affected ranges

Type
GIT
Repo
https://github.com/aimeos/ai-client-html
Events
Type
GIT
Repo
https://github.com/aimeos/ai-client-html
Events
Type
GIT
Repo
https://github.com/aimeos/ai-client-html
Events
Type
GIT
Repo
https://github.com/aimeos/ai-client-html
Events

Affected versions

2021.*

2021.10.1
2021.10.10
2021.10.11
2021.10.12
2021.10.13
2021.10.14
2021.10.15
2021.10.16
2021.10.17
2021.10.18
2021.10.19
2021.10.2
2021.10.20
2021.10.21
2021.10.3
2021.10.4
2021.10.5
2021.10.6
2021.10.7
2021.10.8
2021.10.9

2024.*

2024.04.1
2024.04.2
2024.04.3
2024.04.4
2024.04.5
2024.04.6