- Description
- Saleor is an e-commerce platform. From 2.0.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, Saleor supports query batching by submitting multiple GraphQL operations in a single HTTP request as a JSON array but wasn't enforcing any upper limit on the number of operations. This allowed an unauthenticated attacker to send a single HTTP request many operations (bypassing the per query complexity limit) to exhaust resources. This vulnerability is fixed in 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118.
- Source
- security-advisories@github.com
- NVD status
- Analyzed
- Products
- saleor
CVSS 3.1
- Type
- Secondary
- Base score
- 7.5
- Impact score
- 3.6
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Severity
- HIGH
- security-advisories@github.com
- CWE-770
- Hype score
- Not currently trending
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:saleor:saleor:*:*:*:*:*:*:*:*",
"matchCriteriaId": "1B4A5EA6-A42E-41BA-9A75-20C9FF65EE98",
"versionEndExcluding": "3.20.118",
"versionStartIncluding": "2.0.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:saleor:saleor:*:*:*:*:*:*:*:*",
"matchCriteriaId": "2312AF3F-A049-4E4B-AAEF-21D7B5463A3A",
"versionEndExcluding": "3.21.54",
"versionStartIncluding": "3.21.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:saleor:saleor:*:*:*:*:*:*:*:*",
"matchCriteriaId": "ABB6E342-967D-4F4D-9869-BC24C630ACEF",
"versionEndExcluding": "3.22.47",
"versionStartIncluding": "3.22.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:saleor:saleor:3.23.0:alpha0:*:*:*:*:*:*",
"matchCriteriaId": "086CBDFF-B1C4-4AD4-9F39-00B028E29338",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:saleor:saleor:3.23.0:alpha1:*:*:*:*:*:*",
"matchCriteriaId": "404B7EE8-9CE0-4B8D-B0B7-2DF60F355E72",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:saleor:saleor:3.23.0:alpha2:*:*:*:*:*:*",
"matchCriteriaId": "6DD7D745-F558-4CBE-9110-2F7DCBCF4D2F",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]