MEDIUM
Internal exception message exposure for login action in Sylius
Published Dec 5, 2019
4.3
MEDIUMCVSS 3.1
EPSS 0.75%
Description
In affected versions of Sylius, exception messages from internal exceptions (like database exception) are wrapped by \Symfony\Component\Security\Core\Exception\AuthenticationServiceException and propagated through the system to UI. Therefore, some internal system information may leak and be visible to the customer. A validation message with the exception details will be presented to the user when one will try to log into the shop. This has been patched in versions 1.3.14, 1.4.10, 1.5.7, and 1.6.3.
Affected products
-
- Version < 1.3.14StatusaffectedConstraints<1.3.14
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- https://github.com/Sylius/Sylius/commit/be245302dfc594d8690fe50dd47631d186aa945f x_refsource_MISCRelease Notes
- https://github.com/Sylius/Sylius/security/advisories/GHSA-3r8j-pmch-5j2h x_refsource_CONFIRMMitigationThird Party Advisory
- https://github.com/advisories/GHSA-3r8j-pmch-5j2h Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-16768
| Link | Providers | Tags |
|---|---|---|
| https://github.com/Sylius/Sylius/commit/be245302dfc594d8690fe50dd47631d186aa945f | x_refsource_MISCRelease Notes | |
| https://github.com/Sylius/Sylius/security/advisories/GHSA-3r8j-pmch-5j2h | x_refsource_CONFIRMMitigationThird Party Advisory | |
| https://github.com/advisories/GHSA-3r8j-pmch-5j2h | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-16768 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Dec 5, 2019
Updated Aug 5, 2024
Reserved Sep 24, 2019
Link CVE-2019-16768
CISA Vulnrichment
GHSA-3R8J-PMCH-5J2H Updated n/a