PT-2023-20451 · Saleor · Saleor

Nyankiyoshi

·

Publicado

2023-03-02

·

Atualizado

2023-03-13

·

CVE-2023-26051

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Saleor versions prior to 3.1.48 Saleor versions prior to 3.7.59 Saleor versions prior to 3.8.30 Saleor versions prior to 3.9.27 Saleor versions prior to 3.10.14 Saleor versions prior to 3.11.12
Description The issue arises from internal Python exceptions not being handled properly, resulting in error messages being returned via the API. These messages may contain sensitive information, such as user email addresses, particularly in staff-authenticated requests.
Recommendations For versions prior to 3.1.48, update to version 3.1.48 or later. For versions prior to 3.7.59, update to version 3.7.59 or later. For versions prior to 3.8.30, update to version 3.8.30 or later. For versions prior to 3.9.27, update to version 3.9.27 or later. For versions prior to 3.10.14, update to version 3.10.14 or later. For versions prior to 3.11.12, update to version 3.11.12 or later.

Exploit

Correção

Generation of Error Message Containing Sensitive Information

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-26051
GHSA-R8QR-WWG3-2R85

Produtos afetados

Saleor