#VU24806 Information disclosure in Saleor - CVE-2020-7964

 

#VU24806 Information disclosure in Saleor - CVE-2020-7964

Published: January 31, 2020


Vulnerability identifier: #VU24806
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2020-7964
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Saleor
Software vendor:
Mirumee Labs

Description

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to incorrect access control in the "checkoutCustomerAttach" mutations. A remote attacker can attach their checkouts to any user ID and consequently leak user data (e.g., name, address, and previous orders of any other customer)


Remediation

Install updates from vendor's website.

External links