ai-client-html is an Aimeos e-commerce HTML client component. Debug information revealed sensitive information from environment variables in error log. This issue has been patched in versions 2024.04.7, 2023.10.15, 2022.10.13 and 2021.10.22.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/38xxx/CVE-2024-38516.json",
"cwe_ids": [
"CWE-1295"
],
"cna_assigner": "GitHub_M"
}{
"versions": [
{
"introduced": "2024.04.1"
},
{
"fixed": "2024.04.7"
}
]
}{
"versions": [
{
"introduced": "2023.04.1"
},
{
"fixed": "2023.10.15"
}
]
}