漏洞标题
N/A
漏洞描述信息
在Sylius v2.0.2中存在速率限制问题,允许远程攻击者对用户账户执行不受限制的暴力破解攻击,显著增加账户被攻破的风险及合法用户的服务中断风险。
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
漏洞类别
过多认证尝试的限制不恰当
漏洞标题
N/A
漏洞描述信息
A rate limiting issue in Sylius v2.0.2 allows a remote attacker to perform unrestricted brute-force attacks on user accounts, significantly increasing the risk of account compromise and denial of service for legitimate users. The Supplier's position is that the Sylius core software is not intended to address brute-force attacks; instead, customers deploying a Sylius-based system are supposed to use "firewalls, rate-limiting middleware, or authentication providers" for that functionality.
CVSS信息
N/A
漏洞类别
N/A
漏洞标题
Sylius 安全漏洞
漏洞描述信息
Sylius是波兰Sylius公司的一套基于Symfony框架的开源电子商务平台。 Sylius v2.0.2版本存在安全漏洞,该漏洞源于包含一个速率限制问题。攻击者利用该漏洞可以进行暴力破解攻击,可能导致账户被盗用及拒绝服务。
CVSS信息
N/A
漏洞类别
其他