{"id":"GHSA-g8pg-33v4-9r96","summary":"Thelia authentication bypass vulnerability","details":"An authentication bypass was identifed in thelia/thelia project for customer and admin. This vulnerability is present from version 2.0.0-beta1 and is fixed in 2.1.3 and 2.2.0-alpha1.","modified":"2026-07-17T18:30:27.884445483Z","published":"2024-05-30T13:26:47Z","database_specific":{"github_reviewed_at":"2024-05-30T13:26:47Z","nvd_published_at":null,"cwe_ids":["CWE-287"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/github/advisory-database/pull/8012"},{"type":"WEB","url":"https://github.com/thelia/thelia/commit/028cfcf507cd8685772e156ec0c860034d407094"},{"type":"WEB","url":"https://github.com/thelia/thelia/commit/71c1cee66d8f2e515e82478f792879fa63843644"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/thelia/thelia/2015-04-13-1.yaml"},{"type":"PACKAGE","url":"https://github.com/thelia/thelia"},{"type":"WEB","url":"https://web.archive.org/web/20160502224630/http://thelia.net/version-2-1-3-with-security-fix"}],"affected":[{"package":{"name":"thelia/thelia","ecosystem":"Packagist","purl":"pkg:composer/thelia/thelia"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.0.0-beta1"},{"fixed":"2.1.3"}]}],"versions":["2.0.0","2.0.0-RC1","2.0.0-beta1","2.0.0-beta2","2.0.0-beta3","2.0.0-beta4","2.0.1","2.0.10","2.0.11","2.0.12","2.0.2","2.0.3","2.0.3-beta","2.0.3-beta2","2.0.4","2.0.5","2.0.6","2.0.7","2.0.8","2.0.9","2.1.0","2.1.0-alpha1","2.1.0-alpha2","2.1.0-beta1","2.1.0-beta2","2.1.1","2.1.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/05/GHSA-g8pg-33v4-9r96/GHSA-g8pg-33v4-9r96.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"}]}