Lucene search

K
cve[email protected]CVE-2024-29888
HistoryMar 27, 2024 - 7:15 p.m.

CVE-2024-29888

2024-03-2719:15:49
CWE-359
web.nvd.nist.gov
26
saleor e-commerce
pickup
local stock
vulnerability
patched
versions
nvd

4.2 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N

4.4 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

13.0%

Saleor is an e-commerce platform that serves high-volume companies. When using Pickup: Local stock only click-and-collect as a delivery method in specific conditions the customer could overwrite the warehouse address with its own, which exposes its address as click-and-collect address. This issue has been patched in versions: 3.14.61, 3.15.37, 3.16.34, 3.17.32, 3.18.28, 3.19.15.

Affected configurations

Vulners
Node
saleorsaleorRange3.14.563.14.61
OR
saleorsaleorRange3.15.313.15.37
OR
saleorsaleorRange3.16.273.16.34
OR
saleorsaleorRange3.17.253.17.32
OR
saleorsaleorRange3.18.193.18.28
OR
saleorsaleorRange3.19.53.19.15
VendorProductVersionCPE
saleorsaleor*cpe:2.3:a:saleor:saleor:*:*:*:*:*:*:*:*
saleorsaleor*cpe:2.3:a:saleor:saleor:*:*:*:*:*:*:*:*
saleorsaleor*cpe:2.3:a:saleor:saleor:*:*:*:*:*:*:*:*
saleorsaleor*cpe:2.3:a:saleor:saleor:*:*:*:*:*:*:*:*
saleorsaleor*cpe:2.3:a:saleor:saleor:*:*:*:*:*:*:*:*
saleorsaleor*cpe:2.3:a:saleor:saleor:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "saleor",
    "product": "saleor",
    "versions": [
      {
        "version": ">= 3.14.56, < 3.14.61",
        "status": "affected"
      },
      {
        "version": ">= 3.15.31, < 3.15.37",
        "status": "affected"
      },
      {
        "version": ">= 3.16.27, < 3.16.34",
        "status": "affected"
      },
      {
        "version": ">= 3.17.25, < 3.17.32",
        "status": "affected"
      },
      {
        "version": ">= 3.18.19, < 3.18.28",
        "status": "affected"
      },
      {
        "version": ">= 3.19.5, < 3.19.15",
        "status": "affected"
      }
    ]
  }
]

4.2 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N

4.4 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

13.0%

Related for CVE-2024-29888