VulnerabilityModified
CVE-2022-24742
Sylius is an open source eCommerce platform.
MEDIUM 5.5EPSS 0.82%
Does this matter?
Lower severity and a low EPSS score (0.82%). Track it; it rarely justifies an emergency change on its own.
Description
Sylius is an open source eCommerce platform. Prior to versions 1.9.10, 1.10.11, and 1.11.2, any other user can view the data if browser tab remains unclosed after log out. The issue is fixed in versions 1.9.10, 1.10.11, and 1.11.2. A workaround is available. The application must strictly redirect to login page even browser back button is pressed. Another possibility is to set more strict cache policies for restricted content.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
- EPSS
- 0.82% probability · 55th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200, CWE-668
- Affected
- sylius/sylius
- Source
- security-advisories@github.com
References
- https://github.com/Sylius/Sylius/releases/tag/v1.10.11Release Notes, Third Party Advisory
- https://github.com/Sylius/Sylius/releases/tag/v1.11.2Release Notes, Third Party Advisory
- https://github.com/Sylius/Sylius/releases/tag/v1.9.10Release Notes, Third Party Advisory
- https://github.com/Sylius/Sylius/security/advisories/GHSA-7563-75j9-6h5pMitigation, Third Party Advisory
- https://github.com/Sylius/Sylius/releases/tag/v1.10.11Release Notes, Third Party Advisory
- https://github.com/Sylius/Sylius/releases/tag/v1.11.2Release Notes, Third Party Advisory
- https://github.com/Sylius/Sylius/releases/tag/v1.9.10Release Notes, Third Party Advisory
- https://github.com/Sylius/Sylius/security/advisories/GHSA-7563-75j9-6h5pMitigation, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.