SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-1010304

The attack vector is: Unauthenticated user can access the GraphQL API (which is by default publicly exposed under `/graphql/` URL) and fetch products data which may include admin-restricted shop's revenue data.

MEDIUM 5.3EPSS 1.17%

Does this matter?

Lower severity and a low EPSS score (1.17%). Track it; it rarely justifies an emergency change on its own.

Description

Saleor Issue was introduced by merge commit: e1b01bad0703afd08d297ed3f1f472248312cc9c. This commit was released as part of 2.0.0 release is affected by: Incorrect Access Control. The impact is: Important. The component is: ProductVariant type in GraphQL API. The attack vector is: Unauthenticated user can access the GraphQL API (which is by default publicly exposed under `/graphql/` URL) and fetch products data which may include admin-restricted shop's revenue data. The fixed version is: 2.3.1.

CVSS 3.0
5.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS
1.17% probability · 66th percentile
CISA KEV
Not listed
Weakness
CWE-862
Affected
mirumee/saleor
Source
josh@bress.net

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.