GHSA-v7px-46v9-5qwp

Suggest an improvement
Source
https://github.com/advisories/GHSA-v7px-46v9-5qwp
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/03/GHSA-v7px-46v9-5qwp/GHSA-v7px-46v9-5qwp.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-v7px-46v9-5qwp
Aliases
Published
2024-03-25T19:43:06Z
Modified
2024-03-25T22:32:32.720712Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
Storefront user can access history and most viewed data from matching back-office user with the same ID
Details

Impact

Navigation history, most viewed and favorite navigation items are returned to storefront user in JSON navigation response if ID of storefront user matches ID of back-office user.

Database specific
{
    "nvd_published_at": "2024-03-25T19:15:57Z",
    "cwe_ids": [
        "CWE-200"
    ],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2024-03-25T19:43:06Z"
}
References

Affected packages

Packagist / oro/customer-portal

Package

Name
oro/customer-portal
Purl
pkg:composer/oro/customer-portal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.1.0
Last affected
4.1.13

Affected versions

4.*

4.1.0
4.1.1-rc
4.1.1-rc2
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.1.9
4.1.10
4.1.11
4.1.12
4.1.13

Packagist / oro/customer-portal

Package

Name
oro/customer-portal
Purl
pkg:composer/oro/customer-portal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.2.0
Last affected
4.2.10

Affected versions

4.*

4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.2.8

Packagist / oro/customer-portal

Package

Name
oro/customer-portal
Purl
pkg:composer/oro/customer-portal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.0.0
Last affected
5.0.11

Affected versions

5.*

5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.0.10
5.0.11

Packagist / oro/customer-portal

Package

Name
oro/customer-portal
Purl
pkg:composer/oro/customer-portal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.1.0
Fixed
5.1.4

Affected versions

5.*

5.1.0
5.1.1
5.1.2
5.1.3

Database specific

{
    "last_known_affected_version_range": "<= 5.1.3"
}