CVE-2024-57610: High severity sylius vulnerability
Withdrawn Advisory This advisory has been withdrawn because it is not a vulnerability in the Sylius framework. This link is maintained to preserve external references.
Original Description A rate limiting issue in Sylius v2.0.2 allows a remote attacker to perform unrestricted brute-force attacks on user accounts, significantly increasing the risk of account compromise and denial of service for legitimate users. The Supplier's position is that the Sylius core software is not intended to address brute-force attacks; instead, customers deploying a Sylius-based system are supposed to use "firewalls, rate-limiting middleware, or authentication providers" for that functionality.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-57610?
CVE-2024-57610 has been classified as a withdrawn advisory and is not considered a vulnerability.
How do I fix CVE-2024-57610?
Since CVE-2024-57610 is a withdrawn advisory, there is no fix necessary as it is not a vulnerability.
Which version of Sylius is affected by CVE-2024-57610?
CVE-2024-57610 originally reported an issue with Sylius version 2.0.2.
Can CVE-2024-57610 be exploited by attackers?
CVE-2024-57610 is not an exploitable vulnerability as it has been withdrawn.
Is there any documentation available for CVE-2024-57610?
Documentation regarding CVE-2024-57610 can be found in the records of its withdrawn status.