CVE-2023-32694: Non-constant time HMAC comparison in Adyen plugin in Saleor

Published May 25, 2023
·
Updated

Saleor Core is a composable, headless commerce API. Saleor's validatehmacsignature function is vulnerable to timing attacks. Malicious users could abuse this vulnerability on Saleor deployments having the Adyen plugin enabled in order to determine the secret key and forge fake events, this could affect the database integrity such as marking an order as paid when it is not. This issue has been patched in versions 3.7.68, 3.8.40, 3.9.49, 3.10.36, 3.11.35, 3.12.25, and 3.13.16.

Affected Software

7 affected components
Saleor Saleor>=2.11.0<3.7.68
Saleor Saleor>=3.8.0<3.8.40
Saleor Saleor>=3.9.0<3.9.49
Saleor Saleor>=3.10.0<3.10.36
Saleor Saleor>=3.11.0<3.11.35
Saleor Saleor>=3.12.0<3.12.25
Saleor Saleor>=3.13.0<3.13.16

Event History

May 25, 2023
CVE Published
via MITRE·02:29 PM
Data Sourced
via MITRE·02:29 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2023-32694?

CVE-2023-32694 has a high severity rating due to its potential for timing attacks allowing secret key disclosure.

2

How do I fix CVE-2023-32694?

To fix CVE-2023-32694, update your Saleor installation to a version above 3.13.16 or apply the necessary patches as outlined in the security advisories.

3

Which versions of Saleor are affected by CVE-2023-32694?

Saleor versions from 2.11.0 to 3.13.16 are affected by CVE-2023-32694.

4

What kind of attacks can be performed using CVE-2023-32694?

CVE-2023-32694 allows malicious users to conduct timing attacks to determine the secret key used for HMAC signature validation.

5

Does CVE-2023-32694 affect Saleor installations using the Adyen plugin?

Yes, CVE-2023-32694 specifically affects Saleor installations that have the Adyen plugin enabled.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203