CVE-2022-24742
Exposure of Sensitive Information Due to Incompatible Policies in Sylius
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Sylius is an open source eCommerce platform. Prior to versions 1.9.10, 1.10.11, and 1.11.2, any other user can view the data if browser tab remains unclosed after log out. The issue is fixed in versions 1.9.10, 1.10.11, and 1.11.2. A workaround is available. The application must strictly redirect to login page even browser back button is pressed. Another possibility is to set more strict cache policies for restricted content.
Sylius es una plataforma de comercio electrónico de código abierto. En versiones anteriores a 1.9.10, 1.10.11 y 1.11.2, cualquier otro usuario podía visualizar los datos si la pestaña del navegador permanecía sin cerrar después de cerrar la sesión. El problema ha sido solucionado en versiones 1.9.10, 1.10.11 y 1.11.2. Se presenta una medida de mitigación disponible. La aplicación debe redirigir estrictamente a la página de inicio de sesión incluso si es pulsado el botón de retroceso del navegador. Otra posibilidad es establecer políticas de caché más estrictas para el contenido restringido
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-02-10 CVE Reserved
- 2022-03-14 CVE Published
- 2024-08-03 CVE Updated
- 2024-10-18 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
- CWE-668: Exposure of Resource to Wrong Sphere
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
https://github.com/Sylius/Sylius/releases/tag/v1.10.11 | Release Notes | |
https://github.com/Sylius/Sylius/releases/tag/v1.11.2 | Release Notes | |
https://github.com/Sylius/Sylius/releases/tag/v1.9.10 | Release Notes | |
https://github.com/Sylius/Sylius/security/advisories/GHSA-7563-75j9-6h5p | Mitigation |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Sylius Search vendor "Sylius" | Sylius Search vendor "Sylius" for product "Sylius" | < 1.9.10 Search vendor "Sylius" for product "Sylius" and version " < 1.9.10" | - |
Affected
| ||||||
Sylius Search vendor "Sylius" | Sylius Search vendor "Sylius" for product "Sylius" | >= 1.10.0 < 1.10.11 Search vendor "Sylius" for product "Sylius" and version " >= 1.10.0 < 1.10.11" | - |
Affected
| ||||||
Sylius Search vendor "Sylius" | Sylius Search vendor "Sylius" for product "Sylius" | >= 1.11.0 < 1.11.2 Search vendor "Sylius" for product "Sylius" and version " >= 1.11.0 < 1.11.2" | - |
Affected
|