CVE-2021-4430
Summary
| CVE | CVE-2021-4430 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-11-06 08:15:00 UTC |
| Updated | 2023-11-14 18:04:00 UTC |
| Description | A vulnerability classified as problematic has been found in Ortus Solutions ColdBox Elixir 3.1.6. This affects an unknown part of the file src/defaultConfig.js of the component ENV Variable Handler. The manipulation leads to information disclosure. Upgrading to version 3.1.7 is able to address this issue. The identifier of the patch is a3aa62daea2e44c76d08d1eac63768cd928cd69e. It is recommended to upgrade the affected component. The identifier VDB-244485 was assigned to this vulnerability. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ortussolutions | Coldbox Elixir | 3.1.6 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Fix security vulnerability that echoed out all ENV vars. · Ortus-Solutions/coldbox-elixir@a3aa62d · GitHub | MISC | github.com | |
| Login required | MISC | vuldb.com | |
| Release v3.1.7 · Ortus-Solutions/coldbox-elixir · GitHub | MISC | github.com | |
| CVE-2021-4430: Ortus Solutions ColdBox Elixir ENV Variable defaultConfig.js information disclosure | MISC | vuldb.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.