VYPR
Medium severity4.4NVD Advisory· Published Jan 27, 2020· Updated Jun 17, 2026

CVE-2020-5220

CVE-2020-5220

Description

Sylius ResourceBundle accepts and uses any serialisation groups to be passed via a HTTP header. This might lead to data exposure by using an unintended serialisation group - for example it could make Shop API use a more permissive group from Admin API. Anyone exposing an API with ResourceBundle's controller is affected. The vulnerable versions are: <1.3 || >=1.3.0 <=1.3.12 || >=1.4.0 <=1.4.5 || >=1.5.0 <=1.5.0 || >=1.6.0 <=1.6.2. The patch is provided for Sylius ResourceBundle 1.3.13, 1.4.6, 1.5.1 and 1.6.3, but not for any versions below 1.3.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
sylius/resource-bundlePackagist
>= 1.4.0, < 1.4.61.4.6
sylius/resource-bundlePackagist
>= 1.5.0, < 1.5.11.5.1
sylius/resource-bundlePackagist
>= 1.6.0, < 1.6.31.6.3
sylius/syliusPackagist
< 1.3.121.3.12
sylius/syliusPackagist
>= 1.4.0, < 1.4.41.4.4
sylius/resource-bundlePackagist
>= 1.0.0, < 1.3.131.3.13

Affected products

5
  • cpe:2.3:a:sylius:syliusresourcebundle:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:sylius:syliusresourcebundle:*:*:*:*:*:*:*:*range: >=1.3.0,<=1.3.12
    • cpe:2.3:a:sylius:syliusresourcebundle:1.5.0:*:*:*:*:*:*:*
  • ghsa-coords2 versions
    >= 1.4.0, < 1.4.6+ 1 more
    • (no CPE)range: >= 1.4.0, < 1.4.6
    • (no CPE)range: < 1.3.12
  • Sylius/SyliusResourceBundlev5
    Range: < 1.3.13

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.