Skip to content

Detailed Error Report is Displayed in Production Environment

High
kenjis published GHSA-hwxf-qxj7-7rfj Oct 26, 2023

Package

composer codeigniter4/framework (Composer)

Affected versions

4.4.2

Patched versions

4.4.3

Description

Impact

If an error or exception occurs, a detailed error report is displayed even if in the production environment.
As a result, confidential information may be leaked.

Patches

Upgrade to v4.4.3 or later. See upgrading guide.

Workarounds

Replace ini_set('display_errors', '0') with ini_set('display_errors', 'Off') in app/Config/Boot/production.php.

References

For more information

If you have any questions or comments about this advisory:

Severity

High
7.5
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CVE ID

CVE-2023-46240

Weaknesses

Credits