-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| sylius/sylius | composer | <= 2.0.2 |
The vulnerability stems from Sylius' authentication flow not containing built-in rate limiting. While the SecurityController::loginAction is the primary entry point for authentication requests, its vulnerability is contextual - it becomes an attack vector when deployed without complementary security layers like firewalls or rate-limiting middleware. The medium confidence reflects that the vulnerability exists in the absence of security features rather than an explicit code flaw, consistent with the vendor's position that protection is expected to be implemented at the infrastructure level.
Ongoing coverage of React2Shell