A AegiFlow
LOWCVSS 3.7EPSS 0.8%

CVE-2023-26052

Saleor Unauthenticated Information Disclosure Vulnerability via Python Exceptions

Published
2023-03-02
Modified
2026-07-28
EPSS percentile
51%
Aliases
GHSA-3hvj-3cg9-v242
Sources
github-advisory

Summary

### Impact Some internal Python exceptions are not handled properly and thus are returned in API as error messages. Some messages might contain sensitive information like infrastructure details in unauthenticated requests. Affected versions: Saleor ≥ 2.0.0 ### Workarounds None ### For more information If you have any questions or comments about this advisory: * Open a discussion at https://github.com/saleor/saleor/discussions * Email us at [[email protected]](mailto:[email protected])

Affected packages

EcosystemPackageAffected versionsFixed versions
PyPIsaleor3.1.48, 3.11.12, 3.10.14, 3.9.27, 3.8.30, 3.7.59

Remediation: Upgrade to 3.1.48 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.