2024-03-27 21:03:27 +00:00
{
"id" : "CVE-2024-29888" ,
"sourceIdentifier" : "security-advisories@github.com" ,
"published" : "2024-03-27T19:15:49.410" ,
2024-03-28 03:03:20 +00:00
"lastModified" : "2024-03-28T02:01:13.303" ,
"vulnStatus" : "Awaiting Analysis" ,
2024-03-27 21:03:27 +00:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "Saleor is an e-commerce platform that serves high-volume companies. When using `Pickup: Local stock only` click-and-collect as a delivery method in specific conditions the customer could overwrite the warehouse address with its own, which exposes its address as click-and-collect address. This issue has been patched in versions: `3.14.61`, `3.15.37`, `3.16.34`, `3.17.32`, `3.18.28`, `3.19.15`."
}
] ,
"metrics" : {
"cvssMetricV31" : [
{
"source" : "security-advisories@github.com" ,
"type" : "Secondary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N" ,
"attackVector" : "NETWORK" ,
"attackComplexity" : "HIGH" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "REQUIRED" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "LOW" ,
"integrityImpact" : "LOW" ,
"availabilityImpact" : "NONE" ,
"baseScore" : 4.2 ,
"baseSeverity" : "MEDIUM"
} ,
"exploitabilityScore" : 1.6 ,
"impactScore" : 2.5
}
]
} ,
"weaknesses" : [
{
"source" : "security-advisories@github.com" ,
"type" : "Secondary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-359"
}
]
}
] ,
"references" : [
{
"url" : "https://github.com/saleor/saleor/commit/22a1aa3ef0bc54156405f69146788016a7f3f761" ,
"source" : "security-advisories@github.com"
} ,
{
"url" : "https://github.com/saleor/saleor/commit/39abb0f4e4fe6503f81bfbb871227e4f70bcdd5c" ,
"source" : "security-advisories@github.com"
} ,
{
"url" : "https://github.com/saleor/saleor/commit/47cedfd7d6524d79bdb04708edcdbb235874de6b" ,
"source" : "security-advisories@github.com"
} ,
{
"url" : "https://github.com/saleor/saleor/commit/997f7ea4f576543ec88679a86bfe1b14f7f2ff26" ,
"source" : "security-advisories@github.com"
} ,
{
"url" : "https://github.com/saleor/saleor/commit/b7cecda8b603f7472790150bb4508c7b655946d4" ,
"source" : "security-advisories@github.com"
} ,
{
"url" : "https://github.com/saleor/saleor/commit/d8ba545c16ad3153febc5b5be8fd2ef75da9fc95" ,
"source" : "security-advisories@github.com"
} ,
{
"url" : "https://github.com/saleor/saleor/commit/dccc2c842b4e2e09470929c80f07dc137e439182" ,
"source" : "security-advisories@github.com"
} ,
{
"url" : "https://github.com/saleor/saleor/commit/ef003c76a304c89ddb2dc65b7f1d5b3b2ba1c640" ,
"source" : "security-advisories@github.com"
} ,
{
"url" : "https://github.com/saleor/saleor/pull/15694" ,
"source" : "security-advisories@github.com"
} ,
{
"url" : "https://github.com/saleor/saleor/pull/15697" ,
"source" : "security-advisories@github.com"
} ,
{
"url" : "https://github.com/saleor/saleor/security/advisories/GHSA-mrj3-f2h4-7w45" ,
"source" : "security-advisories@github.com"
}
]
}