CVE-2023-32065

Source
https://nvd.nist.gov/vuln/detail/CVE-2023-32065
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-32065.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2023-32065
Aliases
Published
2023-11-28T03:36:57.823Z
Modified
2025-11-29T14:15:35.877672Z
Severity
  • 5.8 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N CVSS Calculator
Summary
OroCommerce get-totals-for-checkout API endpoint returns unwanted data
Details

OroCommerce is an open-source Business to Business Commerce application built with flexibility in mind. Detailed Order totals information may be received by Order ID. This issue is patched in version 5.0.11 and 5.1.1.

Database specific
{
    "cna_assigner": "GitHub_M",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/32xxx/CVE-2023-32065.json",
    "cwe_ids": [
        "CWE-284"
    ]
}
References

Affected packages

Git / github.com/oroinc/orocommerce

Affected ranges

Type
GIT
Repo
https://github.com/oroinc/orocommerce
Events
Database specific
{
    "versions": [
        {
            "introduced": "4.2.0"
        },
        {
            "last_affected": "4.2.10"
        }
    ]
}
Type
GIT
Repo
https://github.com/oroinc/orocommerce
Events
Database specific
{
    "versions": [
        {
            "introduced": "5.0.0"
        },
        {
            "fixed": "5.0.11"
        }
    ]
}
Type
GIT
Repo
https://github.com/oroinc/orocommerce
Events
Database specific
{
    "versions": [
        {
            "introduced": "5.1.0"
        },
        {
            "fixed": "5.1.1"
        }
    ]
}

Affected versions

4.*

4.2.0
4.2.1
4.2.10
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.2.8
4.2.9

5.*

5.0.0
5.0.1
5.0.10
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0

Database specific

source

"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-32065.json"