PT-2020-14173 · Saleor · Saleor Storefront

Lowpatryspublished

·

Published

2020-06-30

·

Updated

2020-07-28

·

CVE-2020-15085

CVSS v3.1

6.9

Medium

VectorAV:N/AC:H/PR:N/UI:R/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Saleor Storefront versions prior to 2.10.3
Description The issue concerns the caching of request data used for customer authentication in the browser's local storage, which includes sensitive credentials. A malicious user with direct access to the browser could potentially extract the email and password. In versions prior to 2.10.0, the cache persisted even after the user logged out.
Recommendations For versions prior to 2.10.3, update to version 2.10.3 to resolve the issue. As a temporary workaround for versions prior to 2.10.3, consider manually clearing the application data (browser's local storage) after logging into Saleor Storefront.

Fix

Cleartext Storage of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-15085
GHSA-4279-H39W-2JQM

Affected Products

Saleor Storefront