CVE-2020-15146: Injection Vulnerability
(updated )
In SyliusResourceBundle request parameters injected inside an expression evaluated by symfony/expression-language
package haven’t been sanitized properly. This allows the attacker to access any public service by manipulating that request parameter, allowing for Remote Code Execution.
References
Detect and mitigate CVE-2020-15146 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →