QID 981948
QID 981948: Python (pip) Security Update for saleor (GHSA-rgcm-rpq9-9cgr)
An issue was discovered in Mirumee Saleor 2.x before 2.9.1. Incorrect access control in the checkoutCustomerAttach mutations allows attackers to attach their checkouts to any user ID and consequently leak user data (e.g., name, address, and previous orders of any other customer).
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-rgcm-rpq9-9cgr for updates pertaining to this vulnerability.
Vendor References
- GHSA-rgcm-rpq9-9cgr -
github.com/advisories/GHSA-rgcm-rpq9-9cgr
CVEs related to QID 981948
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-rgcm-rpq9-9cgr | saleor |
|