CVE-2020-7964
Missing Authentication for Critical Function in Saleor
5.3
MEDIUM
CVSS 3.1
EPSS 0.32%
Description
An issue was discovered in Mirumee Saleor 2.x before 2.9.1. Incorrect access control in the checkoutCustomerAttach mutations allows attackers to attach their checkouts to any user ID and consequently leak user data (e.g., name, address, and previous orders of any other customer).
How to fix CVE-2020-7964
To remediate CVE-2020-7964, upgrade the affected package to a fixed version below.
- —upgrade to 2.9.1 or later
Is CVE-2020-7964 being exploited?
Low — EPSS is 0.3%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- >= 2.0.0, < 2.9.1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.3 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |