CVE-2020-5220: Ability to expose data in Sylius by using an unintended serialisation group
Impact
ResourceBundle accepts and uses any serialisation groups to be passed via a HTTP header. This might lead to data exposure by using an unintended serialisation group - for example it could make Shop API use a more permissive group from Admin API.
Anyone exposing an API with ResourceBundle's controller is affected. The vulnerable versions are: <1.3 || >=1.3.0 <=1.3.12 || >=1.4.0 <=1.4.5 || >=1.5.0 <=1.5.0 || >=1.6.0 <=1.6.2.
Patches
The patch is provided for ResourceBundle 1.3.13, 1.4.6, 1.5.1 and 1.6.3, but not for any versions below 1.3.
After it is applied, It allows to choose only the groups that are defined in serializationgroups or allowedserializationgroups route definition. Any group not defined in those will not be used.
This behaviour might be a BC break for those using custom groups via the HTTP header, please adjust allowedserializationgroups accordingly.
Workarounds
Service sylius.resourcecontroller.requestconfigurationfactory can be overridden with an implementation copied from \Sylius\Bundle\ResourceBundle\Controller\RequestConfigurationFactory where the part that handles custom serialisation groups is deleted.
Other sources
CVE-2020-5220: Ability to define unintended serialisation groups via HTTP header which might lead to data exposure
Sylius ResourceBundle accepts and uses any serialisation groups to be passed via a HTTP header. This might lead to data exposure by using an unintended serialisation group - for example it could make Shop API use a more permissive group from Admin API. Anyone exposing an API with ResourceBundle's controller is affected. The vulnerable versions are: <1.3 || >=1.3.0 <=1.3.12 || >=1.4.0 <=1.4.5 || >=1.5.0 <=1.5.0 || >=1.6.0 <=1.6.2. The patch is provided for Sylius ResourceBundle 1.3.13, 1.4.6, 1.5.1 and 1.6.3, but not for any versions below 1.3.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/sylius/resource-bundleto a version that resolves this vulnerability.Fixed in 1.3.13 - Upgrade
Upgrade
composer/sylius/syliusto a version that resolves this vulnerability.Fixed in 1.4.4 - Upgrade
Upgrade
composer/sylius/syliusto a version that resolves this vulnerability.Fixed in 1.3.12 - Upgrade
Upgrade
composer/sylius/resource-bundleto a version that resolves this vulnerability.Fixed in 1.6.3 - Upgrade
Upgrade
composer/sylius/resource-bundleto a version that resolves this vulnerability.Fixed in 1.5.1 - Upgrade
Upgrade
composer/sylius/resource-bundleto a version that resolves this vulnerability.Fixed in 1.4.6 - Upgrade
Upgrade
Sylius ResourceBundleto a version that resolves this vulnerability.Fixed in 1.3.13 - Upgrade
Upgrade
Sylius ResourceBundleto a version that resolves this vulnerability.Fixed in 1.4.6 - Upgrade
Upgrade
Sylius ResourceBundleto a version that resolves this vulnerability.Fixed in 1.5.1 - Upgrade
Upgrade
Sylius ResourceBundleto a version that resolves this vulnerability.Fixed in 1.6.3 - Configuration
After applying the fix, adjust your route configuration for ResourceBundle controllers so that `allowed_serialization_groups` (or `serialization_groups`) includes only the intended groups; any group not defined there will not be used.
Sylius ResourceBundle allowed_serialization_groups = Set to only the serialization groups you want to allow via the HTTP header (groups defined in serialization_groups or allowed_serialization_groups route definition will be the only groups used)
Event History
Frequently Asked Questions
What is CVE-2020-5220?
CVE-2020-5220 is a vulnerability in Sylius ResourceBundle that allows the definition of unintended serialization groups via an HTTP header, potentially leading to data exposure.
What is the severity of CVE-2020-5220?
The severity of CVE-2020-5220 is medium, with a CVSS score of 5.3.
Which software versions are affected by CVE-2020-5220?
Versions 1.0.0 to 1.4.4 of Sylius and Versions 1.0.0 to 1.6.3 of Sylius ResourceBundle are affected by CVE-2020-5220.
How can CVE-2020-5220 be fixed?
To fix CVE-2020-5220, it is recommended to update Sylius and Sylius ResourceBundle to versions that include the security patches.
Where can I find more information about CVE-2020-5220?
More information about CVE-2020-5220 can be found in the following references: [link 1](https://github.com/Sylius/SyliusResourceBundle/security/advisories/GHSA-8vp7-j5cj-vvm2) and [link 2](https://github.com/FriendsOfPHP/security-advisories/blob/master/sylius/resource-bundle/CVE-2020-5220.yaml).