Description
In Mirumee Saleor 2.7.0 (fixed in 2.8.0), CSRF protection middleware was accidentally disabled, which allowed attackers to send a POST request without a valid CSRF token and be accepted by the server.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-3777 | In Mirumee Saleor 2.7.0 (fixed in 2.8.0), CSRF protection middleware was accidentally disabled, which allowed attackers to send a POST request without a valid CSRF token and be accepted by the server. |
Github GHSA |
GHSA-fgjh-x3f8-8gmh | Mirumee Saleor CSRF Protection Disabled |
References
| Link | Providers |
|---|---|
| https://github.com/mirumee/saleor/releases/tag/2.8.0 |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T23:57:39.445Z
Reserved: 2019-07-14T00:00:00.000Z
Link: CVE-2019-13594
No data.
Status : Modified
Published: 2019-07-14T17:15:11.243
Modified: 2024-11-21T04:25:17.603
Link: CVE-2019-13594
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA