Junglewise Threat Intelligence

CVE-2024-29888: Saleor information leak in Local stock only pickup method

CVE-2024-29888 · Severity: medium · CVSS 4.2 · Published 2024-03-28

Technologies: saleor (PyPI), Saleor. Vendors: PyPI, Saleor.

Executive brief

Saleor is an e-commerce platform used by high-volume businesses to manage online stores. A flaw in the 'Local stock only' pickup delivery method allows a customer's private home address to accidentally overwrite a warehouse's public address. This results in the exposure of private customer location data to other users or the public, potentially impacting customer privacy and the company's reputation for data handling.

Technical details

A vulnerability exists in Saleor's click-and-collect functionality, specifically when using the 'Pickup: Local stock only' delivery method. Under certain conditions, a customer's address can overwrite the warehouse address in the system, leading to the exposure of private personal information (CWE-359). The attack vector is network-based but requires high complexity and user interaction to trigger the specific conditions for the address overwrite. Successful exploitation results in a loss of confidentiality for customer data. Patches are available in versions 3.14.61, 3.15.37, 3.16.34, 3.17.32, 3.18.28, and 3.19.15.

Affected products

  • Saleor Saleor >= 3.14.56, < 3.14.61; >= 3.15.31, < 3.15.37; >= 3.16.27, < 3.16.34; >= 3.17.25, < 3.17.32; >= 3.18.19, < 3.18.28; >= 3.19.5, < 3.19.15

Timeline

  • 2024-03-27: disclosed
  • 2024-03-27: patched
  • 2024-03-28: advisory

References

Related threats