Impact
The vulnerability resides in the get_client_ip function of Saleor’s throttling.py. The function fails to properly restrict repeated authentication attempts because the IP address used to enforce throttling can be spoofed, especially under most deployments that rely on the XFF header. This allows an attacker to perform a brute‑force login attempt from a single temporary address that is not correctly recorded, thereby bypassing the intended rate‑limit and potentially compromising user accounts. While the vendor has framed the behavior as intended with a correctly configured XFF, the absence of proper validation introduces a real security risk.
Affected Systems
Saleor versions up to 3.20.118, 3.21.54, 3.22.47, and 3.23.14 are affected. The issue is implemented in the saleor/account/throttling.py module of the Saleor open‑source e‑commerce framework.
Risk and Exploitability
The CVSS score of 6.3 classifies the weakness as moderate, but the EPSS score is below 1 percent, indicating a very low probability that the vulnerability is actively exploited at this time. The issue is not currently listed in CISA’s KEV catalog and is reported to be exploitable remotely, yet the exploit requires high technical complexity and is considered difficult to execute. Attackers would need to manipulate the XFF header or otherwise spoof the client IP to avoid the throttling logic, a scenario typically possible only in environments with misconfigured proxies or where IP spoofing is permitted.
OpenCVE Enrichment