CVE-2023-32694

Saleor Core is a composable, headless commerce API. Saleor's `validate_hmac_signature` function is vulnerable to timing attacks. Malicious users could abuse this vulnerability on Saleor deployments having the Adyen plugin enabled in order to determine the secret key and forge fake events, this could affect the database integrity such as marking an order as paid when it is not. This issue has been patched in versions 3.7.68, 3.8.40, 3.9.49, 3.10.36, 3.11.35, 3.12.25, and 3.13.16.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:saleor:saleor:*:*:*:*:*:*:*:*
cpe:2.3:a:saleor:saleor:*:*:*:*:*:*:*:*
cpe:2.3:a:saleor:saleor:*:*:*:*:*:*:*:*
cpe:2.3:a:saleor:saleor:*:*:*:*:*:*:*:*
cpe:2.3:a:saleor:saleor:*:*:*:*:*:*:*:*
cpe:2.3:a:saleor:saleor:*:*:*:*:*:*:*:*
cpe:2.3:a:saleor:saleor:*:*:*:*:*:*:*:*

History

01 Jun 2023, 17:21

Type Values Removed Values Added
References (MISC) https://github.com/saleor/saleor/commit/1328274e1a3d04ab87d7daee90229ff47b3bc35e - (MISC) https://github.com/saleor/saleor/commit/1328274e1a3d04ab87d7daee90229ff47b3bc35e - Patch
References (MISC) https://github.com/saleor/saleor/security/advisories/GHSA-3rqj-9v87-2x3f - (MISC) https://github.com/saleor/saleor/security/advisories/GHSA-3rqj-9v87-2x3f - Vendor Advisory
First Time Saleor
Saleor saleor
CWE CWE-208
CPE cpe:2.3:a:saleor:saleor:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4

25 May 2023, 15:58

Type Values Removed Values Added
New CVE

Information

Published : 2023-05-25 15:15

Updated : 2023-12-10 15:01


NVD link : CVE-2023-32694

Mitre link : CVE-2023-32694

CVE.ORG link : CVE-2023-32694


JSON object : View

Products Affected

saleor

  • saleor
CWE
CWE-203

Observable Discrepancy

CWE-208

Observable Timing Discrepancy