| Summary | In solidus before versions 2.8.6, 2.9.6, and 2.10.2, there is an bility to change order address without triggering address validations. This vulnerability allows a malicious customer to craft request data with parameters that allow changing the address of the current order without changing the shipment costs associated with the new shipment. All stores with at least two shipping zones and different costs of shipment per zone are impacted. This problem comes from how checkout permitted attributes are structured. We have a single list of attributes that are permitted across the whole checkout, no matter the step that is being submitted. See the linked reference for more information. As a workaround, if it is not possible to upgrade to a supported patched version, please use this gist in the references section. |
|---|---|
| Publication Date | Aug. 5, 2020, 8:15 a.m. |
| Registration Date | Jan. 26, 2021, 11:53 a.m. |
| Last Update | Nov. 21, 2024, 2:04 p.m. |
| CVSS3.1 : MEDIUM | |
| スコア | 5.3 |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
| 攻撃元区分(AV) | ネットワーク |
| 攻撃条件の複雑さ(AC) | 低 |
| 攻撃に必要な特権レベル(PR) | 不要 |
| 利用者の関与(UI) | 不要 |
| 影響の想定範囲(S) | 変更なし |
| 機密性への影響(C) | なし |
| 完全性への影響(I) | 低 |
| 可用性への影響(A) | なし |
| CVSS2.0 : MEDIUM | |
| Score | 5.0 |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
| 攻撃元区分(AV) | ネットワーク |
| 攻撃条件の複雑さ(AC) | 低 |
| 攻撃前の認証要否(Au) | 不要 |
| 機密性への影響(C) | なし |
| 完全性への影響(I) | 低 |
| 可用性への影響(A) | なし |
| Get all privileges. | いいえ |
| Get user privileges | いいえ |
| Get other privileges | いいえ |
| User operation required | いいえ |
| Configuration1 | or higher | or less | more than | less than | |
| cpe:2.3:a:nebulab:solidus:*:*:*:*:*:*:*:* | 2.8.6 | ||||
| cpe:2.3:a:nebulab:solidus:*:*:*:*:*:*:*:* | 2.10.0 | 2.10.2 | |||
| cpe:2.3:a:nebulab:solidus:*:*:*:*:*:*:*:* | 2.9.0 | 2.9.6 | |||
| Title | solidus における入力確認に関する脆弱性 |
|---|---|
| Summary | solidus には、入力確認に関する脆弱性が存在します。 |
| Possible impacts | 情報を改ざんされる可能性があります。 |
| Solution | ベンダより正式な対策が公開されています。ベンダ情報を参照して適切な対策を実施してください。 |
| Publication Date | July 16, 2020, midnight |
| Registration Date | Oct. 16, 2020, 3:32 p.m. |
| Last Update | Oct. 16, 2020, 3:32 p.m. |
| Nebulab |
| Solidus 2.10.2 未満 |
| Solidus 2.8.6 未満 |
| Solidus 2.9.6 未満 |
| No | Changed Details | Date of change |
|---|---|---|
| 1 | [2020年10月16日] 掲載 |
Oct. 16, 2020, 3:32 p.m. |