CVE-2022-24733
Summary
| CVE | CVE-2022-24733 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-03-14 19:15:00 UTC |
| Updated | 2022-03-22 17:32:00 UTC |
| Description | Sylius is an open source eCommerce platform. Prior to versions 1.9.10, 1.10.11, and 1.11.2, it is possible for a page controlled by an attacker to load the website within an iframe. This will enable a clickjacking attack, in which the attacker's page overlays the target application's interface with a different interface provided by the attacker. The issue is fixed in versions 1.9.10, 1.10.11, and 1.11.2. A workaround is available. Every response from app should have an X-Frame-Options header set to: ``sameorigin``. To achieve that, add a new `subscriber` in the app. |
Risk And Classification
Problem Types: CWE-1021
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Release v1.9.10 · Sylius/Sylius · GitHub | MISC | github.com | |
| Release v1.10.11 · Sylius/Sylius · GitHub | MISC | github.com | |
| Add missing HTTP headers to avoid login forms clickjacking · Advisory · Sylius/Sylius · GitHub | CONFIRM | github.com | |
| Release v1.11.2 · Sylius/Sylius · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.