{"id":"CVE-2023-32694","summary":"Non-constant time HMAC comparison in Adyen plugin in Saleor","details":"Saleor Core is a composable, headless commerce API. Saleor's `validate_hmac_signature` function is vulnerable to timing attacks. Malicious users could abuse this vulnerability on Saleor deployments having the Adyen plugin enabled in order to determine the secret key and forge fake events, this could affect the database integrity such as marking an order as paid when it is not. This issue has been patched in versions 3.7.68, 3.8.40, 3.9.49, 3.10.36, 3.11.35, 3.12.25, and 3.13.16.","aliases":["GHSA-3rqj-9v87-2x3f"],"modified":"2026-08-12T03:51:40.919467826Z","published":"2023-05-25T14:29:10.217Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/32xxx/CVE-2023-32694.json","cna_assigner":"GitHub_M","cwe_ids":["CWE-203","CWE-208"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/32xxx/CVE-2023-32694.json"},{"type":"ADVISORY","url":"https://github.com/saleor/saleor/security/advisories/GHSA-3rqj-9v87-2x3f"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-32694"},{"type":"FIX","url":"https://github.com/saleor/saleor/commit/1328274e1a3d04ab87d7daee90229ff47b3bc35e"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/saleor/saleor","events":[{"introduced":"3b31391b92b184b591ef4e85ff6a59cd52cdad98"},{"fixed":"d5c1455c207c7709cc4cf165250e31f21ce07d5b"},{"introduced":"f5b8251d0c9fc2e56b877c2c32eba297af98fb1a"},{"fixed":"8b0dbb3dd21c058c8b0775ff1f03ef0e3d005590"},{"introduced":"14fab7d68a25f52281b12dee7154c38682292339"},{"fixed":"e0ae5bc4176f5d994c2ed109c77fe03b4e39d34c"},{"introduced":"792acfb0fb764a8074f4e7e3e2c28a32d43f81f9"},{"fixed":"92982774d0236f121e368ab408422c1bb65febaf"},{"introduced":"7a0e3851927c6fed03cff68e8e032843e0959754"},{"fixed":"f06d1081cfe2b8e7679b6feb23ac050a2001fb7d"},{"introduced":"033c3a266b9d76706742ae6d1b35d571f46c801c"},{"fixed":"84d4feb82d9d921df1e3afb383599d1f9041da39"},{"introduced":"f42298280d84bfbd331184b022223758d30492bd"},{"fixed":"fd058ffba61391679f671cf8c34e02e97c0aaa07"},{"fixed":"1328274e1a3d04ab87d7daee90229ff47b3bc35e"}],"database_specific":{"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:saleor:saleor:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"2.11.0"},{"fixed":"3.7.68"},{"introduced":"3.8.0"},{"fixed":"3.8.40"},{"introduced":"3.9.0"},{"fixed":"3.9.49"},{"introduced":"3.10.0"},{"fixed":"3.10.36"},{"introduced":"3.11.0"},{"fixed":"3.11.35"},{"introduced":"3.12.0"},{"fixed":"3.12.25"},{"introduced":"3.13.0"},{"fixed":"3.13.16"}]}}],"versions":["3.13.15","3.9.48","3.8.39","3.12.24","3.11.34","3.10.35","3.8.38","3.9.47","3.10.34","3.11.33","3.12.23","3.13.14","3.13.13","3.12.22","3.13.12","3.9.46","3.13.11","3.12.21","3.11.32","3.10.33","3.10.32","3.11.31","3.12.20","3.13.10","3.8.37","3.9.45","3.10.31","3.11.30","3.12.19","3.13.9","3.10.30","3.11.29","3.12.18","3.13.8","3.12.17","3.13.7","3.13.6","3.12.16","3.11.28","3.10.29","3.9.44","3.13.5","3.13.4","3.11.27","3.10.28","3.12.15","3.9.43","3.8.36","3.9.42","3.10.27","3.11.26","3.12.14","3.13.3","3.13.2","3.12.13","3.10.26","3.9.41","3.8.35","3.8.32","3.9.29","3.11.15","3.11.25","3.13.1","3.12.12","3.11.24","3.10.25","3.8.34","3.13.0","3.9.40","3.12.11","3.11.23","3.9.39","3.12.10","3.11.22","3.10.24","3.10.23","3.9.38","3.12.9","3.11.21","3.11.20","3.12.8","3.10.22","3.9.37","3.8.33","3.9.36","3.10.21","3.11.19","3.12.7","3.11.18","3.10.20","3.9.35","3.12.6","3.9.34","3.10.19","3.11.17","3.12.5","3.10.18","3.11.16","3.12.4","3.9.33","3.12.3","3.10.17","3.9.32","3.8.31","3.12.2","3.11.14","3.10.16","3.9.31","3.11.13","3.10.15","3.9.30","3.8.30","3.12.1","3.12.0","3.9.28","3.9.27","3.10.14","3.11.12","3.11.11","3.10.13","3.9.26","3.8.29","3.11.10","3.10.12","3.9.25","3.9.24","3.8.28","3.10.11","3.9.23","3.11.9","3.11.8","3.10.10","3.9.22","3.11.7","3.10.9","3.9.21","3.10.8","3.11.6","3.9.20","3.10.7","3.11.5","3.8.27","3.9.19","3.11.4","3.10.6","3.11.3","3.8.26","3.9.18","3.11.2","3.10.5","3.8.25","3.11.1","3.10.4","3.9.17","3.11.0","3.10.3","3.8.24","3.9.16","3.10.2","3.9.15","3.9.14","3.10.1","3.10.0","3.9.13","3.9.12","3.8.23","3.9.11","3.9.9","3.8.22","3.9.8","3.9.7","3.8.21","3.8.20","3.9.6","3.9.5","3.8.19","3.9.4","3.8.18","3.9.3","3.8.17","3.9.2","3.9.1","3.9.0","3.8.16","3.8.15","3.8.14","3.8.13","3.8.12","3.8.11","3.8.10","3.8.9","3.8.8","3.8.7","3.8.6","3.8.5","3.8.4","3.8.3","3.8.2","3.8.1","3.8.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-32694.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"}]}