{"id":"DRUPAL-CONTRIB-2021-032","details":"This module provides a system for building an ecommerce solution in their Drupal site.\n\nThe module doesn't sufficiently verify access to profile data in certain circumstances.\n\nThis vulnerability is mitigated by the fact that an attacker must have permission to perform the checkout operation.","modified":"2026-09-10T03:45:36.762430494Z","published":"2021-09-22T16:51:57Z","references":[{"type":"WEB","url":"https://www.drupal.org/sa-contrib-2021-032"}],"affected":[{"package":{"name":"drupal/commerce","ecosystem":"Packagist:https://packages.drupal.org/8","purl":"pkg:composer/drupal/commerce?repository_url=https:%2F%2Fpackages.drupal.org%2F8"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.27.0"}],"database_specific":{"constraint":"\u003c2.27.0"}}],"database_specific":{"affected_versions":"\u003c2.27.0","source":"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/commerce/DRUPAL-CONTRIB-2021-032.json"}}],"schema_version":"1.9.0","credits":[{"name":"Sasanka Jandhyala","contact":["https://www.drupal.org/user/3541248"]}]}