CVE-2024-57610
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Feb 6, 2025
Updated: Feb 7, 2025
CWE ID 307
Summary
CVE-2024-57610 is a rate limiting issue discovered in Sylius v2.0.2 that exposes user accounts to unrestricted brute-force attacks. An attacker can exploit this vulnerability remotely, leading to a heightened risk of account compromise and denial of service for legitimate users. Although Sylius core software doesn't address brute-force protection, it is recommended for users to employ external solutions, such as firewalls, rate-limiting middleware, or authentication providers, as a countermeasure.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share