CVE-2024-29036: Saleor Storefront session leak in cache

Published Mar 20, 2024
·
Updated

Saleor Storefront is software for building e-commerce experiences. Prior to commit 579241e75a5eb332ccf26e0bcdd54befa33f4783, when any user authenticates in the storefront, anonymous users are able to access their data. The session is leaked through cache and can be accessed by anyone. Users should upgrade to a version that incorporates commit 579241e75a5eb332ccf26e0bcdd54befa33f4783 or later to receive a patch. A possible workaround is to temporarily disable authentication by changing the usage of createSaleorAuthClient().

Affected Software

2 affected components
Saleor Storefront<579241e75a5eb332ccf26e0bcdd54befa33f4783
Saleor react-storefront<1.0.2

Event History

Mar 20, 2024
CVE Published
via MITRE·08:39 PM
Data Sourced
via MITRE·08:39 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 PM
RemedyDescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2024-29036?

CVE-2024-29036 is considered a high severity vulnerability due to its potential to leak sensitive user session data.

2

How do I fix CVE-2024-29036?

To fix CVE-2024-29036, upgrade the Saleor Storefront software to a version later than commit 579241e75a5eb332ccf26e0bcdd54befa33f4783.

3

What does CVE-2024-29036 affect?

CVE-2024-29036 affects the Saleor Storefront prior to the specified commit, allowing unauthorized access to authenticated user data.

4

Who is affected by CVE-2024-29036?

All Saleor Storefront users who have not updated their version to include the fix are at risk from CVE-2024-29036.

5

What type of vulnerability is CVE-2024-29036?

CVE-2024-29036 is a session management vulnerability that allows anonymous users to access authenticated session data.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203