Incorrect Access Control in Saleor's GraphQL API
CVE-2019-1010304

5.3MEDIUM

Key Information:

Vendor

Saleor

Status
Vendor
CVE Published:
15 July 2019

What is CVE-2019-1010304?

A vulnerability exists in Saleor's GraphQL API that allows unauthenticated users to access data endpoints, including sensitive revenue information restricted to administrators. This issue originates from a specific commit in the product's release, exposing the ProductVariant type and making critical data accessible through the publicly exposed /graphql/ URL. Users are advised to upgrade to version 2.3.1 or later to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Saleor Issue was introduced by merge commit: e1b01bad0703afd08d297ed3f1f472248312cc9c. This commit was released as part of 2.0.0 release [fixed: 2.3.1]

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.