CVE-2019-1010304: Medium severity saleor vulnerability

Published Jul 15, 2019
·
Updated

Saleor Issue was introduced by merge commit: e1b01bad0703afd08d297ed3f1f472248312cc9c. This commit was released as part of 2.0.0 release is affected by: Incorrect Access Control. The impact is: Important. The component is: ProductVariant type in GraphQL API. The attack vector is: Unauthenticated user can access the GraphQL API (which is by default publicly exposed under /graphql/ URL) and fetch products data which may include admin-restricted shop's revenue data. The fixed version is: 2.3.1.

Affected Software

1 affected component
Mirumee Saleor>=2.0.0<2.3.1

Event History

Jul 15, 2019
CVE Published
via MITRE·02:45 PM
Data Sourced
via MITRE·02:45 PM
DescriptionWeakness

Frequently Asked Questions

1

Which deployments are realistically exposed?

Saleor installations running a release affected by this issue are exposed if their GraphQL endpoint is publicly reachable. The endpoint is publicly exposed at /graphql/ by default.

2

What does an attacker need to exploit this issue?

No authentication or user interaction is required. An attacker only needs network access to the publicly exposed GraphQL API to query product data.

3

What information could be exposed?

The affected ProductVariant GraphQL API can return product data that may include shop revenue information normally restricted to administrators. The stated impact is information disclosure; integrity and availability are not affected.

4

What should be done if the deployment cannot be patched immediately?

Upgrade to Saleor 2.3.1, which is identified as the fixed version. If patching cannot happen immediately, restricting unauthenticated access to the /graphql/ endpoint addresses the described attack path.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203