PT-2019-14824 · Sylius · Sylius

Pamil

·

Publicado

2019-12-05

·

Atualizado

2019-12-17

·

CVE-2019-16768

CVSS v3.1

4.3

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Sylius versions prior to 1.3.14 Sylius versions prior to 1.4.10 Sylius versions prior to 1.5.7 Sylius versions prior to 1.6.3
Description In affected versions of Sylius, exception messages from internal exceptions, such as database exceptions, are wrapped by SymfonyComponentSecurityCoreExceptionAuthenticationServiceException and propagated through the system to the UI. This may cause some internal system information to leak and be visible to the customer. A validation message with the exception details will be presented to the user when they try to log into the shop.
Recommendations For Sylius versions prior to 1.3.14, update to version 1.3.14 or later. For Sylius versions prior to 1.4.10, update to version 1.4.10 or later. For Sylius versions prior to 1.5.7, update to version 1.5.7 or later. For Sylius versions prior to 1.6.3, update to version 1.6.3 or later. As a temporary workaround, override the src/Sylius/Bundle/UiBundle/Resources/views/Security/ login.html.twig file and replace lines with the provided code to prevent exception details from being displayed to the user.

Correção

Generation of Error Message Containing Sensitive Information

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-16768
GHSA-3R8J-PMCH-5J2H

Produtos afetados

Sylius