CVE-2020-5220: Ability to expose data in Sylius by using an unintended serialisation group

Published Jan 27, 2020
·
Updated

Impact

ResourceBundle accepts and uses any serialisation groups to be passed via a HTTP header. This might lead to data exposure by using an unintended serialisation group - for example it could make Shop API use a more permissive group from Admin API.

Anyone exposing an API with ResourceBundle's controller is affected. The vulnerable versions are: <1.3 || >=1.3.0 <=1.3.12 || >=1.4.0 <=1.4.5 || >=1.5.0 <=1.5.0 || >=1.6.0 <=1.6.2.

Patches

The patch is provided for ResourceBundle 1.3.13, 1.4.6, 1.5.1 and 1.6.3, but not for any versions below 1.3.

After it is applied, It allows to choose only the groups that are defined in serializationgroups or allowedserializationgroups route definition. Any group not defined in those will not be used.

This behaviour might be a BC break for those using custom groups via the HTTP header, please adjust allowedserializationgroups accordingly.

Workarounds

Service sylius.resourcecontroller.requestconfigurationfactory can be overridden with an implementation copied from \Sylius\Bundle\ResourceBundle\Controller\RequestConfigurationFactory where the part that handles custom serialisation groups is deleted.

Other sources

CVE-2020-5220: Ability to define unintended serialisation groups via HTTP header which might lead to data exposure

Sylius ResourceBundle accepts and uses any serialisation groups to be passed via a HTTP header. This might lead to data exposure by using an unintended serialisation group - for example it could make Shop API use a more permissive group from Admin API. Anyone exposing an API with ResourceBundle's controller is affected. The vulnerable versions are: <1.3 || >=1.3.0 <=1.3.12 || >=1.4.0 <=1.4.5 || >=1.5.0 <=1.5.0 || >=1.6.0 <=1.6.2. The patch is provided for Sylius ResourceBundle 1.3.13, 1.4.6, 1.5.1 and 1.6.3, but not for any versions below 1.3.

Affected Software

12 affected componentsFixes available
composer/sylius/sylius>=1.0.0, <1.1.0, >=1.1.0, <1.2.0, >=1.2.0, <1.3.0, >=1.3.0, <1.3.12, >=1.4.0, <1.4.4
composer/sylius/resource-bundle>=1.0.0, <1.1.0, >=1.1.0, <1.2.0, >=1.2.0, <1.3.0, >=1.3.0, <1.3.13, >=1.4.0, <1.4.6, >=1.5.0, <1.5.1, >=1.6.0, <1.6.3
composer/sylius/resource-bundle>=1.0.0<1.3.13
1.3.13
composer/sylius/sylius>=1.4.0<1.4.4
1.4.4
composer/sylius/sylius<1.3.12
1.3.12
composer/sylius/resource-bundle>=1.6.0<1.6.3
1.6.3
composer/sylius/resource-bundle>=1.5.0<1.5.1
1.5.1
composer/sylius/resource-bundle>=1.4.0<1.4.6
1.4.6
Sylius SyliusResourceBundle>=1.3.0<=1.3.12
Sylius SyliusResourceBundle>=1.4.0<=1.4.5
Sylius SyliusResourceBundle>=1.6.0<=1.6.2
Sylius SyliusResourceBundle=1.5.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade composer/sylius/resource-bundle to a version that resolves this vulnerability.

    Fixed in 1.3.13
  2. Upgrade

    Upgrade composer/sylius/sylius to a version that resolves this vulnerability.

    Fixed in 1.4.4
  3. Upgrade

    Upgrade composer/sylius/sylius to a version that resolves this vulnerability.

    Fixed in 1.3.12
  4. Upgrade

    Upgrade composer/sylius/resource-bundle to a version that resolves this vulnerability.

    Fixed in 1.6.3
  5. Upgrade

    Upgrade composer/sylius/resource-bundle to a version that resolves this vulnerability.

    Fixed in 1.5.1
  6. Upgrade

    Upgrade composer/sylius/resource-bundle to a version that resolves this vulnerability.

    Fixed in 1.4.6
  7. Upgrade

    Upgrade Sylius ResourceBundle to a version that resolves this vulnerability.

    Fixed in 1.3.13
  8. Upgrade

    Upgrade Sylius ResourceBundle to a version that resolves this vulnerability.

    Fixed in 1.4.6
  9. Upgrade

    Upgrade Sylius ResourceBundle to a version that resolves this vulnerability.

    Fixed in 1.5.1
  10. Upgrade

    Upgrade Sylius ResourceBundle to a version that resolves this vulnerability.

    Fixed in 1.6.3
  11. Configuration

    After applying the fix, adjust your route configuration for ResourceBundle controllers so that `allowed_serialization_groups` (or `serialization_groups`) includes only the intended groups; any group not defined there will not be used.

    Sylius ResourceBundle allowed_serialization_groups = Set to only the serialization groups you want to allow via the HTTP header (groups defined in serialization_groups or allowed_serialization_groups route definition will be the only groups used)

Event History

Jan 27, 2020
Advisory Published
01:54 PM
CVE Published
via MITRE·08:15 PM
Data Sourced
via MITRE·08:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is CVE-2020-5220?

CVE-2020-5220 is a vulnerability in Sylius ResourceBundle that allows the definition of unintended serialization groups via an HTTP header, potentially leading to data exposure.

2

What is the severity of CVE-2020-5220?

The severity of CVE-2020-5220 is medium, with a CVSS score of 5.3.

3

Which software versions are affected by CVE-2020-5220?

Versions 1.0.0 to 1.4.4 of Sylius and Versions 1.0.0 to 1.6.3 of Sylius ResourceBundle are affected by CVE-2020-5220.

4

How can CVE-2020-5220 be fixed?

To fix CVE-2020-5220, it is recommended to update Sylius and Sylius ResourceBundle to versions that include the security patches.

5

Where can I find more information about CVE-2020-5220?

More information about CVE-2020-5220 can be found in the following references: [link 1](https://github.com/Sylius/SyliusResourceBundle/security/advisories/GHSA-8vp7-j5cj-vvm2) and [link 2](https://github.com/FriendsOfPHP/security-advisories/blob/master/sylius/resource-bundle/CVE-2020-5220.yaml).

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203