PT-2022-20595 · Mprweb · Mprweb

Lowhwittenborn

·

Published

2022-08-01

·

Updated

2022-08-09

·

CVE-2022-31185

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions mprweb (affected versions not specified)
Description mprweb is a hosting platform for the makedeb Package Repository. Email addresses were not hidden, even if a user had clicked the Hide Email Address checkbox on their account page, or during signup. This could lead to an account's email being leaked, which may be problematic if your email needs to remain private for any reason.
Recommendations To resolve the issue, users hosting their own mprweb instance will need to upgrade to the latest commit. Users on the official instance will already have this issue fixed. As a temporary workaround, consider restricting access to email addresses until the issue is resolved.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-31185
GHSA-JM39-H693-678G

Affected Products

Mprweb