Information disclosure in Saleor - CVE-2020-7964

 

Information disclosure in Saleor - CVE-2020-7964

Published: January 31, 2020


Vulnerability identifier: #VU24806
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-7964
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to incorrect access control in the "checkoutCustomerAttach" mutations. A remote attacker can attach their checkouts to any user ID and consequently leak user data (e.g., name, address, and previous orders of any other customer)


Affected software

Saleor

How to mitigate CVE-2020-7964

Install updates from vendor's website.

Saleor - update to 2.9.1

External References

Related Security Bulletins