Vulnerability Description
SyliusGridBundle is a package of generic data grids for Symfony applications. Prior to versions 1.10.1 and 1.11-rc2, values added at the end of query sorting were passed directly to the database. The maintainers do not know if this could lead to direct SQL injections but took steps to remediate the vulnerability. The issue is fixed in versions 1.10.1 and 1.11-rc2. As a workaround, overwrite the`Sylius\Component\Grid\Sorting\Sorter.php` class and register it in the container. More information about this workaround is available in the GitHub Security Advisory.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sylius | Syliusgridbundle | < 1.10.1 |
Related Weaknesses (CWE)
References
- https://github.com/Sylius/SyliusGridBundle/commit/73d0791d0575f955e830a3da4c3345PatchThird Party Advisory
- https://github.com/Sylius/SyliusGridBundle/pull/222PatchThird Party Advisory
- https://github.com/Sylius/SyliusGridBundle/releases/tag/v1.10.1Release NotesThird Party Advisory
- https://github.com/Sylius/SyliusGridBundle/releases/tag/v1.11.0-RC.2Release NotesThird Party Advisory
- https://github.com/Sylius/SyliusGridBundle/security/advisories/GHSA-2xmm-g482-44Third Party Advisory
- https://github.com/Sylius/SyliusGridBundle/commit/73d0791d0575f955e830a3da4c3345PatchThird Party Advisory
- https://github.com/Sylius/SyliusGridBundle/pull/222PatchThird Party Advisory
- https://github.com/Sylius/SyliusGridBundle/releases/tag/v1.10.1Release NotesThird Party Advisory
- https://github.com/Sylius/SyliusGridBundle/releases/tag/v1.11.0-RC.2Release NotesThird Party Advisory
- https://github.com/Sylius/SyliusGridBundle/security/advisories/GHSA-2xmm-g482-44Third Party Advisory
FAQ
What is CVE-2022-24752?
CVE-2022-24752 is a vulnerability with a CVSS score of 9.8 (CRITICAL). SyliusGridBundle is a package of generic data grids for Symfony applications. Prior to versions 1.10.1 and 1.11-rc2, values added at the end of query sorting were passed directly to the database. The ...
How severe is CVE-2022-24752?
CVE-2022-24752 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2022-24752?
Check the references section above for vendor advisories and patch information. Affected products include: Sylius Syliusgridbundle.