CVE-2020-15085
CVSS V2 Low 2.1
CVSS V3 Medium 6.1
Description
In Saleor Storefront before version 2.10.3, request data used to authenticate customers was inadvertently cached in the browser's local storage mechanism, including credentials. A malicious user with direct access to the browser could extract the email and password. In versions prior to 2.10.0 persisted the cache even after the user logged out. This is fixed in version 2.10.3. A workaround is to manually clear application data (browser's local storage) after logging into Saleor Storefront.
Overview
- CVE ID
- CVE-2020-15085
- Assigner
- security-advisories@github.com
- Vulnerability Status
- Analyzed
- Published Version
- 2020-06-30T17:15:10
- Last Modified Date
- 2020-07-28T15:45:59
Weakness Enumerations
CPE Configuration (Product)
CPE | Vulnerable | Operator | Version Start | Version End |
---|---|---|---|---|
cpe:2.3:a:mirumee:saleor:*:*:*:*:*:*:*:* | 1 | OR | 2.10.3 |
CVSS Version 2
- Version
- 2.0
- Vector String
- AV:L/AC:L/Au:N/C:P/I:N/A:N
- Access Vector
- LOCAL
- Access Compatibility
- LOW
- Authentication
- NONE
- Confidentiality Impact
- PARTIAL
- Integrity Impact
- NONE
- Availability Impact
- NONE
- Base Score
- 2.1
- Severity
- LOW
- Exploitability Score
- 3.9
- Impact Score
- 2.9
CVSS Version 3
- Version
- 3.1
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
- Attack Vector
- LOCAL
- Attack Compatibility
- LOW
- Privileges Required
- LOW
- User Interaction
- NONE
- Scope
- UNCHANGED
- Confidentiality Impact
- HIGH
- Availability Impact
- NONE
- Base Score
- 6.1
- Base Severity
- MEDIUM
- Exploitability Score
- 1.8
- Impact Score
- 4.2
References
Reference URL | Reference Tags |
---|---|
https://github.com/mirumee/saleor-storefront/blob/master/CHANGELOG.md#2103 | Release Notes Third Party Advisory |
https://github.com/mirumee/saleor-storefront/security/advisories/GHSA-4279-h39w-2jqm | Third Party Advisory |
https://github.com/mirumee/saleor-storefront/commit/7c331e1be805022c9a7be719bd69d050b2577458 | Patch Third Party Advisory |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2020-15085 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15085 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2022-05-10 16:39:23 | Added to TrackCVE | |||
2022-12-04 19:00:03 | 2020-06-30T17:15Z | 2020-06-30T17:15:10 | CVE Published Date | updated |
2022-12-04 19:00:03 | 2020-07-28T15:45:59 | CVE Modified Date | updated | |
2022-12-04 19:00:03 | Analyzed | Vulnerability Status | updated |