PT-2024-22689 · Unknown · Saleor Storefront

Jyrno42

·

Published

2024-03-20

·

Updated

2025-12-03

·

CVE-2024-29036

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Saleor Storefront versions prior to commit 579241e75a5eb332ccf26e0bcdd54befa33f4783
Description The issue affects Saleor Storefront, software for building e-commerce experiences. When any user authenticates in the storefront, anonymous users are able to access their data. The session is leaked through cache and can be accessed by anyone.
Recommendations To resolve the issue, users should upgrade to a version that incorporates commit 579241e75a5eb332ccf26e0bcdd54befa33f4783 or later to receive a patch. As a temporary workaround, consider disabling authentication by changing the usage of createSaleorAuthClient().

Exploit

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2024-29036
GHSA-52CQ-C7X7-CQW4

Affected Products

Saleor Storefront