PT-2022-27007 · Unknown · Concrete Cms

Adrian Tiron

+1

·

Published

2022-11-14

·

Updated

2025-04-30

·

CVE-2022-43691

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Concrete CMS (formerly concrete5) versions below 8.5.10 Concrete CMS (formerly concrete5) versions between 9.0.0 and 9.1.2
Description The issue inadvertently discloses server-side sensitive information, including secrets in environment variables and server information, when Debug Mode is left on in production.
Recommendations For Concrete CMS (formerly concrete5) versions below 8.5.10, update to version 8.5.10 or later to resolve the issue. For Concrete CMS (formerly concrete5) versions between 9.0.0 and 9.1.2, update to version 9.1.3 or later to resolve the issue. As a temporary workaround, consider disabling Debug Mode in production environments until a patch is applied.

Fix

Cleartext Transmission of Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2022-43691
GHSA-Q3HQ-HM5H-QRX3

Affected Products

Concrete Cms