Lucene search

K
githubGitHub Advisory DatabaseGHSA-MRJ3-F2H4-7W45
HistoryMar 28, 2024 - 5:52 p.m.

Saleor: Customers' addresses leak when using Warehouse as a `Pickup: Local stock only` delivery method

2024-03-2817:52:17
CWE-359
GitHub Advisory Database
github.com
7
saleor
security
address leak
vulnerability
click-and-collect
delivery method

CVSS3

4.2

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N

AI Score

6.7

Confidence

High

EPSS

0

Percentile

13.0%

Summary

Using Pickup: Local stock only as a click-and-collect points could cause a leak of customer addresses

Details

When using Pickup: Local stock only click-and-collect as a delivery method in specific conditions the customer could overwrite the warehouse address with its own, which exposes its address as click-and-collect address.

Impact

The vulnerability can cause the leak of customer’s address when using click-and-collect delivery option marked as Local stock only. It has impact on all orders with click-and-collect delivery method marked as Pickup:Local stock only
The affected versions: >=3.14.56 <3.14.61, >=3.15.31 <3.15.37, >=3.16.27 <3.16.34, >=3.17.25 <3.17.32, >=3.18.19 <3.18.28, >=3.19.5 <3.19.15
This issue has been patched in versions: 3.14.61, 3.15.37, 3.16.34, 3.17.32, 3.18.28, 3.19.15

Workaround

We strongly recommend upgrading to the latest versions, in case of inability to upgrade straight away, possible workarounds are:

References

Affected configurations

Vulners
Node
saleorsaleorRange<3.19.15
OR
saleorsaleorRange<3.18.28
OR
saleorsaleorRange<3.17.32
OR
saleorsaleorRange<3.16.34
OR
saleorsaleorRange<3.15.37
OR
saleorsaleorRange<3.14.61

References

CVSS3

4.2

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N

AI Score

6.7

Confidence

High

EPSS

0

Percentile

13.0%

Related for GHSA-MRJ3-F2H4-7W45