PT-2020-14173 · Saleor · Saleor Storefront
Lowpatryspublished
·
Published
2020-06-30
·
Updated
2020-07-28
·
CVE-2020-15085
CVSS v3.1
6.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Saleor Storefront versions prior to 2.10.3
Description
The issue concerns the caching of request data used for customer authentication in the browser's local storage, which includes sensitive credentials. A malicious user with direct access to the browser could potentially extract the email and password. In versions prior to 2.10.0, the cache persisted even after the user logged out.
Recommendations
For versions prior to 2.10.3, update to version 2.10.3 to resolve the issue.
As a temporary workaround for versions prior to 2.10.3, consider manually clearing the application data (browser's local storage) after logging into Saleor Storefront.
Fix
Cleartext Storage of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Saleor Storefront