PT-2024-22689 · Unknown · Saleor Storefront
Jyrno42
·
Published
2024-03-20
·
Updated
2025-12-03
·
CVE-2024-29036
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Saleor Storefront versions prior to commit 579241e75a5eb332ccf26e0bcdd54befa33f4783
Description
The issue affects Saleor Storefront, software for building e-commerce experiences. When any user authenticates in the storefront, anonymous users are able to access their data. The session is leaked through cache and can be accessed by anyone.
Recommendations
To resolve the issue, users should upgrade to a version that incorporates commit 579241e75a5eb332ccf26e0bcdd54befa33f4783 or later to receive a patch.
As a temporary workaround, consider disabling authentication by changing the usage of
createSaleorAuthClient().Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Saleor Storefront