sylius/sylius is vulnerable to Authentication Bypass
88
High Risk
The Sylius API issues JWTs from separate admin and shop firewalls, but the tokens carry no claim identifying which firewall issued them. Because both firewalls resolve the authenticated user by email across separate user tables, a shop customer whose email matches an administrator can present a shop-issued token to the admin API and be authenticated as that administrator. This grants full administrative access and needs only knowledge of an administrator email address. The fix adds a JwtAudienceListener that stamps an audience and principal claim on issued tokens and verifies both on every request.
You are affected if you are using a version that falls within the vulnerable range and you expose the Sylius API with JWT authentication on both the admin and shop firewalls.
sylius/sylius is vulnerable to Authentication Bypass in versions 1.11.0 - 1.12.24, 1.13.0 - 1.13.16, 1.14.0 - 1.14.19, 2.0.0 - 2.1.15 and 2.2.0 - 2.2.8.
Upgrade the sylius/sylius library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.