CVE-2022-24742

Source
https://nvd.nist.gov/vuln/detail/CVE-2022-24742
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-24742.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-24742
Aliases
Withdrawn
2024-05-15T05:33:29.439847Z
Published
2022-03-14T20:15:08Z
Modified
2023-11-08T04:08:34.698891Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

Sylius is an open source eCommerce platform. Prior to versions 1.9.10, 1.10.11, and 1.11.2, any other user can view the data if browser tab remains unclosed after log out. The issue is fixed in versions 1.9.10, 1.10.11, and 1.11.2. A workaround is available. The application must strictly redirect to login page even browser back button is pressed. Another possibility is to set more strict cache policies for restricted content.

References

Affected packages

Git / github.com/sylius/sylius

Affected ranges