Saleor is a headless, GraphQL commerce platform. In affected versions some GraphQL mutations were not properly checking the ID type input which allowed to access database objects that the authenticated user may not be allowed to access. This vulnerability can be used to expose the following information: Estimating database row counts from tables with a sequential primary key or Exposing staff user and customer email addresses and full name through the `assignNavigation()` mutation. This issue has been patched in main and backported to multiple releases (3.7.17, 3.6.18, 3.5.23, 3.4.24, 3.3.26, 3.2.14, 3.1.24). Users are advised to upgrade. There are no known workarounds for this issue.
Metrics
Affected Vendors & Products
References
History
Thu, 24 Apr 2025 08:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2022-10-06T00:00:00.000Z
Updated: 2025-04-23T16:52:27.439Z
Reserved: 2022-09-02T00:00:00.000Z
Link: CVE-2022-39275

Updated: 2024-08-03T12:00:43.521Z

Status : Modified
Published: 2022-10-06T18:16:17.087
Modified: 2024-11-21T07:17:56.167
Link: CVE-2022-39275

No data.