CVE-2024-29888: Saleor vulnerable to customers addresses leak when using Warehouse as a `Pickup: Local stock only` delivery method

Published Mar 27, 2024
·
Updated

Summary Using Pickup: Local stock only as a click-and-collect points could cause a leak of customer addresses

Details When using Pickup: Local stock only click-and-collect as a delivery method in specific conditions the customer could overwrite the warehouse address with its own, which exposes its address as click-and-collect address.

Impact The vulnerability can cause the leak of customer's address when using click-and-collect delivery option marked as Local stock only. It has impact on all orders with click-and-collect delivery method marked as Pickup:Local stock only The affected versions: >=3.14.56 <3.14.61, >=3.15.31 <3.15.37, >=3.16.27 <3.16.34, >=3.17.25 <3.17.32, >=3.18.19 <3.18.28, >=3.19.5 <3.19.15 This issue has been patched in versions: 3.14.61, 3.15.37, 3.16.34, 3.17.32, 3.18.28, 3.19.15

Workaround We strongly recommend upgrading to the latest versions, in case of inability to upgrade straight away, possible workarounds are: - turn off click-and-collect delivery method on warehouse view when Pickup option is set to Local stock only. - cherry-pick the changes from PRs: https://github.com/saleor/saleor/pull/15694 & https://github.com/saleor/saleor/pull/15697

References - Commits introducing the issue (https://github.com/saleor/saleor/commit/22a1aa3ef0bc54156405f69146788016a7f3f761 main, https://github.com/saleor/saleor/commit/997f7ea4f576543ec88679a86bfe1b14f7f2ff26 3.14, https://github.com/saleor/saleor/commit/ef003c76a304c89ddb2dc65b7f1d5b3b2ba1c640 3.15, https://github.com/saleor/saleor/commit/39abb0f4e4fe6503f81bfbb871227e4f70bcdd5c 3.16, https://github.com/saleor/saleor/commit/b7cecda8b603f7472790150bb4508c7b655946d4 3.17, https://github.com/saleor/saleor/commit/dccc2c842b4e2e09470929c80f07dc137e439182 3.18, https://github.com/saleor/saleor/commit/d8ba545c16ad3153febc5b5be8fd2ef75da9fc95 3.19) - https://github.com/saleor/saleor/commit/47cedfd7d6524d79bdb04708edcdbb235874de6b (main branch) https://github.com/saleor/saleor/releases/tag/3.14.60 https://github.com/saleor/saleor/releases/tag/3.14.61 https://github.com/saleor/saleor/releases/tag/3.15.36 https://github.com/saleor/saleor/releases/tag/3.15.37 https://github.com/saleor/saleor/releases/tag/3.16.33 https://github.com/saleor/saleor/releases/tag/3.16.34 https://github.com/saleor/saleor/releases/tag/3.17.31 https://github.com/saleor/saleor/releases/tag/3.17.32 https://github.com/saleor/saleor/releases/tag/3.18.27 https://github.com/saleor/saleor/releases/tag/3.18.28 https://github.com/saleor/saleor/releases/tag/3.19.14 https://github.com/saleor/saleor/releases/tag/3.19.15

Other sources

Saleor is an e-commerce platform that serves high-volume companies. When using Pickup: Local stock only click-and-collect as a delivery method in specific conditions the customer could overwrite the warehouse address with its own, which exposes its address as click-and-collect address. This issue has been patched in versions: 3.14.61, 3.15.37, 3.16.34, 3.17.32, 3.18.28, 3.19.15.

NVD

Affected Software

12 affected componentsFixes available
pip/saleor>=3.19.5<3.19.15
3.19.15
pip/saleor>=3.18.19<3.18.28
3.18.28
pip/saleor>=3.17.25<3.17.32
3.17.32
pip/saleor>=3.16.27<3.16.34
3.16.34
pip/saleor>=3.15.31<3.15.37
3.15.37
pip/saleor>=3.14.56<3.14.61
3.14.61
Saleor Saleor>=3.14.56<3.14.61
Saleor Saleor>=3.15.31<3.15.37
Saleor Saleor>=3.16.27<3.16.34
Saleor Saleor>=3.17.25<3.17.32
Saleor Saleor>=3.18.19<3.18.28
Saleor Saleor>=3.19.5<3.19.15

Event History

Mar 27, 2024
CVE Published
via MITRE·06:53 PM
Data Sourced
via MITRE·06:53 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 PM
RemedyAffected Software
Mar 28, 2024
Advisory Published
via GitHub·05:52 PM

Frequently Asked Questions

1

What is the severity of CVE-2024-29888?

CVE-2024-29888 is classified as a medium severity vulnerability due to the potential exposure of sensitive customer information.

2

How do I fix CVE-2024-29888?

To remediate CVE-2024-29888, upgrade to the patched versions of Saleor: 3.19.15, 3.18.28, 3.17.32, 3.16.34, 3.15.37, or 3.14.61.

3

What are the affected versions of Saleor for CVE-2024-29888?

CVE-2024-29888 affects Saleor versions between 3.14.56 and 3.14.61, 3.15.31 and 3.15.37, 3.16.27 and 3.16.34, 3.17.25 and 3.17.32, 3.18.19 and 3.18.28, and 3.19.5 and 3.19.15.

4

What type of information is leaked by CVE-2024-29888?

CVE-2024-29888 can lead to the unintended exposure of customer addresses through the use of local stock only click-and-collect points.

5

What conditions trigger CVE-2024-29888?

CVE-2024-29888 is triggered when specific conditions associated with the pickup and delivery methods are met during the checkout process.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203