Description
Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 inadvertently disclose server-side sensitive information (secrets in environment variables and server information) when Debug Mode is left on in production.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-7406 | Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 inadvertently disclose server-side sensitive information (secrets in environment variables and server information) when Debug Mode is left on in production. |
Github GHSA |
GHSA-q3hq-hm5h-qrx3 | Concrete CMS vulnerable to Cleartext Transmission of Sensitive Information |
References
History
Wed, 30 Apr 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-04-30T15:13:11.486Z
Reserved: 2022-10-24T00:00:00.000Z
Link: CVE-2022-43691
Updated: 2024-08-03T13:40:06.483Z
Status : Modified
Published: 2022-11-14T23:15:12.650
Modified: 2025-04-30T16:15:29.283
Link: CVE-2022-43691
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA