CVE-2019-16768
Therefore, some internal system information may leak and be visible to the customer.
Does this matter?
Lower severity and a low EPSS score (0.75%). Track it; it rarely justifies an emergency change on its own.
Description
In affected versions of Sylius, exception messages from internal exceptions (like database exception) are wrapped by \Symfony\Component\Security\Core\Exception\AuthenticationServiceException and propagated through the system to UI. Therefore, some internal system information may leak and be visible to the customer. A validation message with the exception details will be presented to the user when one will try to log into the shop. This has been patched in versions 1.3.14, 1.4.10, 1.5.7, and 1.6.3.
- CVSS 3.1
- 4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 0.75% probability · 53th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-209
- Affected
- sylius/sylius
- Source
- security-advisories@github.com
References
- https://github.com/Sylius/Sylius/commit/be245302dfc594d8690fe50dd47631d186aa945fRelease Notes
- https://github.com/Sylius/Sylius/security/advisories/GHSA-3r8j-pmch-5j2hMitigation, Third Party Advisory
- https://github.com/Sylius/Sylius/commit/be245302dfc594d8690fe50dd47631d186aa945fRelease Notes
- https://github.com/Sylius/Sylius/security/advisories/GHSA-3r8j-pmch-5j2hMitigation, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.