CVE-2020-15085
Summary
| CVE | CVE-2020-15085 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-06-30 17:15:00 UTC |
| Updated | 2020-07-28 15:45:00 UTC |
| Description | In Saleor Storefront before version 2.10.3, request data used to authenticate customers was inadvertently cached in the browser's local storage mechanism, including credentials. A malicious user with direct access to the browser could extract the email and password. In versions prior to 2.10.0 persisted the cache even after the user logged out. This is fixed in version 2.10.3. A workaround is to manually clear application data (browser's local storage) after logging into Saleor Storefront. |
Risk And Classification
Problem Types: CWE-312
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| saleor-storefront/CHANGELOG.md at master · mirumee/saleor-storefront · GitHub | MISC | github.com | Release Notes, Third Party Advisory |
| Merge pull request from GHSA-4279-h39w-2jqm · mirumee/saleor-storefront@7c331e1 · GitHub | MISC | github.com | Patch, Third Party Advisory |
| Client caching login operation with plaintext password · Advisory · mirumee/saleor-storefront · GitHub | CONFIRM | github.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.