{"id":"CVE-2024-29888","summary":"Saleor vulnerable to customers addresses leak when using Warehouse as a `Pickup: Local stock only` delivery method","details":"Saleor is an e-commerce platform that serves high-volume companies. When using `Pickup: Local stock only` click-and-collect as a delivery method in specific conditions the customer could overwrite the warehouse address with its own, which exposes its address as click-and-collect address. This issue has been patched in versions: `3.14.61`, `3.15.37`, `3.16.34`, `3.17.32`, `3.18.28`, `3.19.15`.","aliases":["GHSA-mrj3-f2h4-7w45","PYSEC-2026-1890"],"modified":"2026-08-12T03:51:45.877172899Z","published":"2024-03-27T18:53:44.698Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-359"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/29xxx/CVE-2024-29888.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/29xxx/CVE-2024-29888.json"},{"type":"ADVISORY","url":"https://github.com/saleor/saleor/security/advisories/GHSA-mrj3-f2h4-7w45"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-29888"},{"type":"FIX","url":"https://github.com/saleor/saleor/commit/22a1aa3ef0bc54156405f69146788016a7f3f761"},{"type":"FIX","url":"https://github.com/saleor/saleor/commit/39abb0f4e4fe6503f81bfbb871227e4f70bcdd5c"},{"type":"FIX","url":"https://github.com/saleor/saleor/commit/47cedfd7d6524d79bdb04708edcdbb235874de6b"},{"type":"FIX","url":"https://github.com/saleor/saleor/commit/997f7ea4f576543ec88679a86bfe1b14f7f2ff26"},{"type":"FIX","url":"https://github.com/saleor/saleor/commit/b7cecda8b603f7472790150bb4508c7b655946d4"},{"type":"FIX","url":"https://github.com/saleor/saleor/commit/d8ba545c16ad3153febc5b5be8fd2ef75da9fc95"},{"type":"FIX","url":"https://github.com/saleor/saleor/commit/dccc2c842b4e2e09470929c80f07dc137e439182"},{"type":"FIX","url":"https://github.com/saleor/saleor/commit/ef003c76a304c89ddb2dc65b7f1d5b3b2ba1c640"},{"type":"FIX","url":"https://github.com/saleor/saleor/pull/15694"},{"type":"FIX","url":"https://github.com/saleor/saleor/pull/15697"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/saleor/saleor","events":[{"introduced":"612693af6fbed23f6e72929a2a93e81a306326b2"},{"fixed":"878a50aba3a335565ad7ef440aeade90380dc726"},{"introduced":"dd88f4c4cf8d457e3b1f56eebce590b8ed07f709"},{"fixed":"8f0f6908f204c4e8929f3a2aa75274a9738b7e40"},{"introduced":"58ec424d6d3234c7927072a56387e2fd2f82954a"},{"fixed":"caf4e77f1b118d01373fcdd01bb404b28e92045f"},{"introduced":"ec8421503cd12cbd51747337f1e4560785a07415"},{"fixed":"b3b950229b3c88c720b5b7d187cb530b6afd5779"},{"introduced":"cb3c588d8c697eeaac97e50bf64c40d4ae5fc350"},{"fixed":"7d28717e5b642d913cccf8d2ad7260642ad30a4d"},{"introduced":"30644b29a923bd60bd75e50a7ded7d8fcf20b043"},{"fixed":"faee408b8dfc4ac5d64bfc1282a675af2b62985f"},{"fixed":"22a1aa3ef0bc54156405f69146788016a7f3f761"},{"fixed":"39abb0f4e4fe6503f81bfbb871227e4f70bcdd5c"},{"fixed":"47cedfd7d6524d79bdb04708edcdbb235874de6b"},{"fixed":"997f7ea4f576543ec88679a86bfe1b14f7f2ff26"},{"fixed":"b7cecda8b603f7472790150bb4508c7b655946d4"},{"fixed":"d8ba545c16ad3153febc5b5be8fd2ef75da9fc95"},{"fixed":"dccc2c842b4e2e09470929c80f07dc137e439182"},{"fixed":"ef003c76a304c89ddb2dc65b7f1d5b3b2ba1c640"}],"database_specific":{"extracted_events":[{"introduced":"3.14.56"},{"fixed":"3.14.61"},{"introduced":"3.15.31"},{"fixed":"3.15.37"},{"introduced":"3.16.27"},{"fixed":"3.16.34"},{"introduced":"3.17.25"},{"fixed":"3.17.32"},{"introduced":"3.18.19"},{"fixed":"3.18.28"},{"introduced":"3.19.5"},{"fixed":"3.19.15"}],"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:saleor:saleor:*:*:*:*:*:*:*:*"}}],"versions":["3.15.36","3.16.33","3.17.31","3.18.27","3.19.14","3.14.60","3.18.26","3.17.30","3.16.32","3.15.35","3.14.59","3.19.13","3.18.25","3.19.12","3.19.11","3.17.29","3.16.31","3.15.34","3.14.58","3.18.24","3.16.30","3.19.10","3.18.23","3.19.9","3.18.22","3.17.28","3.16.29","3.15.33","3.14.57","3.19.8","3.19.7","3.18.21","3.17.27","3.17.26","3.16.28","3.15.32","3.19.6","3.18.20","3.14.56","3.15.31","3.16.27","3.17.25","3.18.19","3.19.5"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-29888.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N"}]}