Remote Code Execution (RCE) Affecting sylius/resource-bundle package, versions <1.3.14 >=1.4.0, <1.4.7 >=1.5.0, <1.5.2 >=1.6.0, <1.6.4


0.0
high

Snyk CVSS

    Attack Complexity Low

    Threat Intelligence

    EPSS 0.23% (61st percentile)
Expand this section
NVD
8.8 high

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk ID SNYK-PHP-SYLIUSRESOURCEBUNDLE-598866
  • published 18 Aug 2020
  • disclosed 18 Aug 2020
  • credit Unknown

How to fix?

Upgrade sylius/resource-bundle to version 1.3.14, 1.4.7, 1.5.2, 1.6.4 or higher.

Overview

sylius/resource-bundle is a resource component for Sylius.

Affected versions of this package are vulnerable to Remote Code Execution (RCE) in OptionsParser while using request parameters inside expression language.

References