CVE-2019-16768

In affected versions of Sylius, exception messages from internal exceptions (like database exception) are wrapped by \Symfony\Component\Security\Core\Exception\AuthenticationServiceException and propagated through the system to UI. Therefore, some internal system information may leak and be visible to the customer. A validation message with the exception details will be presented to the user when one will try to log into the shop. This has been patched in versions 1.3.14, 1.4.10, 1.5.7, and 1.6.3.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sylius:sylius:*:*:*:*:*:*:*:*
cpe:2.3:a:sylius:sylius:*:*:*:*:*:*:*:*
cpe:2.3:a:sylius:sylius:*:*:*:*:*:*:*:*
cpe:2.3:a:sylius:sylius:*:*:*:*:*:*:*:*

History

21 Nov 2024, 04:31

Type Values Removed Values Added
References () https://github.com/Sylius/Sylius/commit/be245302dfc594d8690fe50dd47631d186aa945f - Release Notes () https://github.com/Sylius/Sylius/commit/be245302dfc594d8690fe50dd47631d186aa945f - Release Notes
References () https://github.com/Sylius/Sylius/security/advisories/GHSA-3r8j-pmch-5j2h - Mitigation, Third Party Advisory () https://github.com/Sylius/Sylius/security/advisories/GHSA-3r8j-pmch-5j2h - Mitigation, Third Party Advisory
CVSS v2 : 4.0
v3 : 4.3
v2 : 4.0
v3 : 3.5

Information

Published : 2019-12-05 20:15

Updated : 2024-11-21 04:31


NVD link : CVE-2019-16768

Mitre link : CVE-2019-16768

CVE.ORG link : CVE-2019-16768


JSON object : View

Products Affected

sylius

  • sylius
CWE
CWE-209

Generation of Error Message Containing Sensitive Information