{"id":"GHSA-hvgw-gg3p-295j","aliases":[],"url":"https://o3.security/vulnerability/GHSA-hvgw-gg3p-295j","summary":"Read private customer data reclaiming carts in Klaviyo Magento","details":"A researcher identified an endpoint in a thirth party module Klaviyo Magento 2 which allows to read private customer data from stores. It works by reclaiming any guest-cart as your own and reading the private data for the orders in the Magento API.\n\n","published":"2024-05-15T22:03:47Z","modified":"2024-11-29T05:40:37.431105Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"klaviyo/magento2-extension","fixedVersion":"3.0.0"}],"fix":{"url":"https://github.com/klaviyo/magento2-klaviyo/pull/107","label":"klaviyo/magento2-klaviyo#107"},"references":[{"type":"WEB","url":"https://github.com/klaviyo/magento2-klaviyo/pull/107"},{"type":"WEB","url":"https://gist.github.com/JeroenBoersma/f5864a45e3df63b198a57abdff366df2"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/klaviyo/magento2-extension/2021-05-25-1.yaml"},{"type":"PACKAGE","url":"https://github.com/klaviyo/magento2-klaviyo"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-11-29T05:40:37.431105Z"}}