Lucene search

K
cvelistGitHub_MCVELIST:CVE-2023-32694
HistoryMay 25, 2023 - 2:29 p.m.

CVE-2023-32694 Non-constant time HMAC comparison in Adyen plugin in Saleor

2023-05-2514:29:10
CWE-208
CWE-203
GitHub_M
www.cve.org
5
saleor
adyen
hmac
vulnerability
patched
multiple versions

CVSS3

4.8

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N

EPSS

0.001

Percentile

29.6%

Saleor Core is a composable, headless commerce API. Saleor’s validate_hmac_signature function is vulnerable to timing attacks. Malicious users could abuse this vulnerability on Saleor deployments having the Adyen plugin enabled in order to determine the secret key and forge fake events, this could affect the database integrity such as marking an order as paid when it is not. This issue has been patched in versions 3.7.68, 3.8.40, 3.9.49, 3.10.36, 3.11.35, 3.12.25, and 3.13.16.

CNA Affected

[
  {
    "vendor": "saleor",
    "product": "saleor",
    "versions": [
      {
        "version": ">= 2.11.0, < 3.7.68",
        "status": "affected"
      },
      {
        "version": ">= 3.8.0, < 3.8.40",
        "status": "affected"
      },
      {
        "version": ">= 3.9.0, < 3.9.49",
        "status": "affected"
      },
      {
        "version": ">= 3.10.0, < 3.10.36",
        "status": "affected"
      },
      {
        "version": ">= 3.11.0, < 3.11.35",
        "status": "affected"
      },
      {
        "version": ">= 3.12.0, < 3.12.25",
        "status": "affected"
      },
      {
        "version": ">= 3.13.0, < 3.13.16",
        "status": "affected"
      }
    ]
  }
]

CVSS3

4.8

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N

EPSS

0.001

Percentile

29.6%

Related for CVELIST:CVE-2023-32694