CVE-2022-24742

Source
https://cve.org/CVERecord?id=CVE-2022-24742
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-24742.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-24742
Aliases
Published
2022-03-14T19:20:10Z
Modified
2025-12-04T10:17:57.335817Z
Severity
  • 5.0 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N CVSS Calculator
Summary
Exposure of Sensitive Information Due to Incompatible Policies in Sylius
Details

Sylius is an open source eCommerce platform. Prior to versions 1.9.10, 1.10.11, and 1.11.2, any other user can view the data if browser tab remains unclosed after log out. The issue is fixed in versions 1.9.10, 1.10.11, and 1.11.2. A workaround is available. The application must strictly redirect to login page even browser back button is pressed. Another possibility is to set more strict cache policies for restricted content.

Database specific
{
    "cna_assigner": "GitHub_M",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/24xxx/CVE-2022-24742.json",
    "cwe_ids": [
        "CWE-200"
    ]
}
References

Affected packages

Git / github.com/sylius/sylius

Affected ranges

Type
GIT
Repo
https://github.com/sylius/sylius
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "fixed": "1.9.10"
        }
    ]
}
Type
GIT
Repo
https://github.com/sylius/sylius
Events
Database specific
{
    "versions": [
        {
            "introduced": "1.10.0"
        },
        {
            "fixed": "1.10.11"
        }
    ]
}
Type
GIT
Repo
https://github.com/sylius/sylius
Events
Database specific
{
    "versions": [
        {
            "introduced": "1.11.0"
        },
        {
            "fixed": "1.11.2"
        }
    ]
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-24742.json"