CVE-2022-31140
Attackers could use this information for potential data exfiltration, denial of service attacks, enumeration attacks, etc.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.44%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Valinor is a PHP library that helps to map any input into a strongly-typed value object structure. Prior to version 0.12.0, Valinor can use `Throwable#getMessage()` when it should not have permission to do so. This is a problem with cases such as an SQL exception showing an SQL snippet, a database connection exception showing database IP address/username/password, or a timeout detail / out of memory detail. Attackers could use this information for potential data exfiltration, denial of service attacks, enumeration attacks, etc. Version 0.12.0 contains a patch for this vulnerability.
- CVSS 3.1
- 9.1 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
- EPSS
- 1.44% probability · 72th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-209
- Affected
- cuyz/valinor
- Source
- security-advisories@github.com
References
- https://github.com/CuyZ/Valinor/releases/tag/0.12.0Release Notes, Third Party Advisory
- https://github.com/CuyZ/Valinor/security/advisories/GHSA-5pgm-3j3g-2rc7Exploit, Third Party Advisory
- https://github.com/CuyZ/Valinor/releases/tag/0.12.0Release Notes, Third Party Advisory
- https://github.com/CuyZ/Valinor/security/advisories/GHSA-5pgm-3j3g-2rc7Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.