Beveiligingsadvies

CVE-2019-16768

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2019-12-05 20:00:21
Laatst bijgewerkt 2024-08-05 01:24:47
Toegewezen door GitHub_M
CVSS-score 3.5
Status PUBLISHED

Beschrijving

In affected versions of Sylius, exception messages from internal exceptions (like database exception) are wrapped by \Symfony\Component\Security\Core\Exception\AuthenticationServiceException and propagated through the system to UI. Therefore, some internal system information may leak and be visible to the customer. A validation message with the exception details will be presented to the user when one will try to log into the shop. This has been patched in versions 1.3.14, 1.4.10, 1.5.7, and 1.6.3.