{"id":"CVE-2024-38516","summary":"Aimeos HTML client may potentially reveal sensitive information in error log","details":"ai-client-html is an Aimeos e-commerce HTML client component. Debug information revealed sensitive information from environment variables in error log. This issue has been patched in versions 2024.04.7, 2023.10.15, 2022.10.13 and 2021.10.22.","aliases":["GHSA-ppm5-jv84-2xg2"],"modified":"2026-08-12T03:51:16.600931696Z","published":"2024-06-25T20:08:50.779Z","database_specific":{"cwe_ids":["CWE-1295"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/38xxx/CVE-2024-38516.json","cna_assigner":"GitHub_M"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/38xxx/CVE-2024-38516.json"},{"type":"ADVISORY","url":"https://github.com/aimeos/ai-client-html/security/advisories/GHSA-ppm5-jv84-2xg2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-38516"},{"type":"FIX","url":"https://github.com/aimeos/ai-client-html/commit/bb389620ffc3cf4a2f29c11a1e5f512049e0c132"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/aimeos/ai-client-html","events":[{"introduced":"67364361d2e146023cddd73e9ecb7308a37d02dd"},{"introduced":"495cbe5a5238f176cc9c7f3f7cb1bdeda0346f7a"},{"introduced":"28c93f3ab1fe8e16e5d20ae183e0e3094c3239bc"},{"introduced":"b440e27628d62c19b60ca1c01c3928cc191584fc"},{"fixed":"35b80e1ff1dc21c6b5b8fb5d2e817aab92b20b2d"},{"fixed":"f3bc8bd92838254d80338377c9f21ddb42480697"},{"fixed":"cf34990f92e84d304d168895910bfe00dd5d7c86"},{"fixed":"40e1f8219e9101a24c81f54643964877457a0a2d"},{"fixed":"bb389620ffc3cf4a2f29c11a1e5f512049e0c132"}],"database_specific":{"extracted_events":[{"introduced":"2024.04.1"},{"fixed":"2024.04.7"},{"introduced":"2023.04.1"},{"fixed":"2023.10.15"},{"introduced":"2022.04.1"},{"fixed":"2022.10.13"},{"introduced":"2021.10.1"},{"fixed":"2021.10.22"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["2021.10.21","2024.04.6","2024.04.5","2024.04.4","2024.04.3","2024.04.2","2024.04.1","2021.10.20","2021.10.19","2021.10.18","2021.10.17","2021.10.16","2021.10.15","2021.10.14","2021.10.13","2021.10.12","2021.10.11","2021.10.10","2021.10.9","2021.10.8","2021.10.7","2021.10.6","2021.10.5","2021.10.4","2021.10.3","2021.10.2","2021.10.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-38516.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}