CVE-2024-38516: Aimeos Ai-Client-Html

High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.

ai-client-html is an Aimeos e-commerce HTML client component. Debug information revealed sensitive information from environment variables in error log. This issue has been patched in versions 2024.04.7, 2023.10.15, 2022.10.13 and 2021.10.22.

Affected products

  • Aimeos Ai-Client-Html: from 2024.04.1, before 2024.04.7 (fixed in 2024.04.7); from 2023.04.1, before 2023.10.15 (fixed in 2023.10.15); from 2022.04.1, before 2022.10.13 (fixed in 2022.10.13); from 2021.10.1, before 2021.10.22 (fixed in 2021.10.22)

Published 2024-06-25. Last modified 2026-06-17.