Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rgcm-rpq9-9cgr

Опубликовано: 28 июл. 2021
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

Missing Authentication for Critical Function in Saleor

An issue was discovered in Mirumee Saleor 2.x before 2.9.1. Incorrect access control in the checkoutCustomerAttach mutations allows attackers to attach their checkouts to any user ID and consequently leak user data (e.g., name, address, and previous orders of any other customer).

Пакеты

Наименование

saleor

pip
Затронутые версииВерсия исправления

>= 2.0.0, < 2.9.1

2.9.1

EPSS

Процентиль: 54%
0.00315
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-306

Связанные уязвимости

CVSS3: 5.3
nvd
около 6 лет назад

An issue was discovered in Mirumee Saleor 2.x before 2.9.1. Incorrect access control in the checkoutCustomerAttach mutations allows attackers to attach their checkouts to any user ID and consequently leak user data (e.g., name, address, and previous orders of any other customer).

EPSS

Процентиль: 54%
0.00315
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-306