craftcms/cms is vulnerable to Exposure of Sensitive Information
78
High Risk
Craft CMS interpolates referenced environment variables and secrets into a Twig template before rendering it, even when the Twig sandbox is enabled. A string of the form ${ENV_VAR} is replaced with the corresponding environment variable or secrets-file value, giving sandboxed templates access the sandbox is meant to deny. An authenticated control-panel user can incrementally leak secrets through blind error-based rendering, exposing the security key, database and mail credentials, and other secrets. The fix stops secret interpolation in sandboxed template contexts.
You are affected if you are using a version that falls within the vulnerable range and authenticated control-panel users can trigger sandboxed Twig rendering that interpolates ${ENV_VAR}-style secret references (for example via element condition templates).
craftcms/cms is vulnerable to Exposure of Sensitive Information in versions 4.0.0 - 4.18.1 and 5.0.0 - 5.10.5.
Upgrade the craftcms/cms library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant