Skip to main content

Generation of Error Message Containing Sensitive Information

CVE-2023-47639

Severity Medium
Score 5.3/10

Summary

API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. In versions 3.2.0-alpha.1 through 3.2.4, exception messages, that are not HTTP exceptions, are visible in the JSON error response.

  • LOW
  • NETWORK
  • NONE
  • UNCHANGED
  • NONE
  • NONE
  • LOW
  • NONE

CWE-209 - Generation of Error Message Containing Sensitive Information

The software generates an error message that includes sensitive information about its environment, users, or associated data.

Advisory Timeline

  • Published