CVE-2023-32694

Saleor Core is a composable, headless commerce API. Saleor's `validate_hmac_signature` function is vulnerable to timing attacks. Malicious users could abuse this vulnerability on Saleor deployments having the Adyen plugin enabled in order to determine the secret key and forge fake events, this could affect the database integrity such as marking an order as paid when it is not. This issue has been patched in versions 3.7.68, 3.8.40, 3.9.49, 3.10.36, 3.11.35, 3.12.25, and 3.13.16.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:saleor:saleor:*:*:*:*:*:*:*:*
cpe:2.3:a:saleor:saleor:*:*:*:*:*:*:*:*
cpe:2.3:a:saleor:saleor:*:*:*:*:*:*:*:*
cpe:2.3:a:saleor:saleor:*:*:*:*:*:*:*:*
cpe:2.3:a:saleor:saleor:*:*:*:*:*:*:*:*
cpe:2.3:a:saleor:saleor:*:*:*:*:*:*:*:*
cpe:2.3:a:saleor:saleor:*:*:*:*:*:*:*:*

History

21 Nov 2024, 08:03

Type Values Removed Values Added
References () https://github.com/saleor/saleor/commit/1328274e1a3d04ab87d7daee90229ff47b3bc35e - Patch () https://github.com/saleor/saleor/commit/1328274e1a3d04ab87d7daee90229ff47b3bc35e - Patch
References () https://github.com/saleor/saleor/security/advisories/GHSA-3rqj-9v87-2x3f - Vendor Advisory () https://github.com/saleor/saleor/security/advisories/GHSA-3rqj-9v87-2x3f - Vendor Advisory
CVSS v2 : unknown
v3 : 5.4
v2 : unknown
v3 : 4.8

01 Jun 2023, 17:21

Type Values Removed Values Added
References (MISC) https://github.com/saleor/saleor/security/advisories/GHSA-3rqj-9v87-2x3f - (MISC) https://github.com/saleor/saleor/security/advisories/GHSA-3rqj-9v87-2x3f - Vendor Advisory
References (MISC) https://github.com/saleor/saleor/commit/1328274e1a3d04ab87d7daee90229ff47b3bc35e - (MISC) https://github.com/saleor/saleor/commit/1328274e1a3d04ab87d7daee90229ff47b3bc35e - Patch
First Time Saleor
Saleor saleor
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4
CWE CWE-208
CPE cpe:2.3:a:saleor:saleor:*:*:*:*:*:*:*:*

Information

Published : 2023-05-25 15:15

Updated : 2024-11-21 08:03


NVD link : CVE-2023-32694

Mitre link : CVE-2023-32694

CVE.ORG link : CVE-2023-32694


JSON object : View

Products Affected

saleor

  • saleor
CWE
CWE-203

Observable Discrepancy

CWE-208

Observable Timing Discrepancy