CVE-2024-57610: High severity sylius vulnerability

Published Feb 6, 2025
·
Updated

Withdrawn Advisory This advisory has been withdrawn because it is not a vulnerability in the Sylius framework. This link is maintained to preserve external references.

Original Description A rate limiting issue in Sylius v2.0.2 allows a remote attacker to perform unrestricted brute-force attacks on user accounts, significantly increasing the risk of account compromise and denial of service for legitimate users. The Supplier's position is that the Sylius core software is not intended to address brute-force attacks; instead, customers deploying a Sylius-based system are supposed to use "firewalls, rate-limiting middleware, or authentication providers" for that functionality.

Affected Software

3 affected components
composer/sylius/sylius<=2.0.2
Sylius Sylius
Sylius Sylius=2.0.2

Event History

Feb 6, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
Affected Software
Advisory Published
via GitHub·06:31 PM
Feb 7, 2025
Withdrawn
via GitHub·03:25 PM

Frequently Asked Questions

1

What is the severity of CVE-2024-57610?

CVE-2024-57610 has been classified as a withdrawn advisory and is not considered a vulnerability.

2

How do I fix CVE-2024-57610?

Since CVE-2024-57610 is a withdrawn advisory, there is no fix necessary as it is not a vulnerability.

3

Which version of Sylius is affected by CVE-2024-57610?

CVE-2024-57610 originally reported an issue with Sylius version 2.0.2.

4

Can CVE-2024-57610 be exploited by attackers?

CVE-2024-57610 is not an exploitable vulnerability as it has been withdrawn.

5

Is there any documentation available for CVE-2024-57610?

Documentation regarding CVE-2024-57610 can be found in the records of its withdrawn status.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203