GHSA-mrj3-f2h4-7w45

Suggest an improvement
Source
https://github.com/advisories/GHSA-mrj3-f2h4-7w45
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/03/GHSA-mrj3-f2h4-7w45/GHSA-mrj3-f2h4-7w45.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-mrj3-f2h4-7w45
Aliases
Published
2024-03-28T17:52:17Z
Modified
2026-07-28T01:30:31Z
Severity
  • 4.2 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N CVSS Calculator
Summary
Saleor: Customers' addresses leak when using Warehouse as a `Pickup: Local stock only` delivery method
Details

Summary

Using Pickup: Local stock only as a click-and-collect points could cause a leak of customer addresses

Details

When using Pickup: Local stock only click-and-collect as a delivery method in specific conditions the customer could overwrite the warehouse address with its own, which exposes its address as click-and-collect address.

Impact

The vulnerability can cause the leak of customer's address when using click-and-collect delivery option marked as Local stock only. It has impact on all orders with click-and-collect delivery method marked as Pickup:Local stock only The affected versions: >=3.14.56 <3.14.61, >=3.15.31 <3.15.37, >=3.16.27 <3.16.34, >=3.17.25 <3.17.32, >=3.18.19 <3.18.28, >=3.19.5 <3.19.15 This issue has been patched in versions: 3.14.61, 3.15.37, 3.16.34, 3.17.32, 3.18.28, 3.19.15

Workaround

We strongly recommend upgrading to the latest versions, in case of inability to upgrade straight away, possible workarounds are:

References

Database specific
{
    "cwe_ids":  [
        "CWE-359"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2024-03-28T17:52:17Z",
    "nvd_published_at":  "2024-03-27T19:15:49Z",
    "severity":  "MODERATE"
}
References

Affected packages

PyPI
saleor

Package

Name
saleor
View open source insights on deps.dev
Purl
pkg:pypi/saleor

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.14.56
Fixed
3.14.61

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/03/GHSA-mrj3-f2h4-7w45/GHSA-mrj3-f2h4-7w45.json"
saleor

Package

Name
saleor
View open source insights on deps.dev
Purl
pkg:pypi/saleor

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.15.31
Fixed
3.15.37

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/03/GHSA-mrj3-f2h4-7w45/GHSA-mrj3-f2h4-7w45.json"
saleor

Package

Name
saleor
View open source insights on deps.dev
Purl
pkg:pypi/saleor

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.16.27
Fixed
3.16.34

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/03/GHSA-mrj3-f2h4-7w45/GHSA-mrj3-f2h4-7w45.json"
saleor

Package

Name
saleor
View open source insights on deps.dev
Purl
pkg:pypi/saleor

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.17.25
Fixed
3.17.32

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/03/GHSA-mrj3-f2h4-7w45/GHSA-mrj3-f2h4-7w45.json"
saleor

Package

Name
saleor
View open source insights on deps.dev
Purl
pkg:pypi/saleor

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.18.19
Fixed
3.18.28

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/03/GHSA-mrj3-f2h4-7w45/GHSA-mrj3-f2h4-7w45.json"
saleor

Package

Name
saleor
View open source insights on deps.dev
Purl
pkg:pypi/saleor

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.19.5
Fixed
3.19.15

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/03/GHSA-mrj3-f2h4-7w45/GHSA-mrj3-f2h4-7w45.json"