MEDIUM5.8
GHSA-88g2-xgh9-4ph2
OroCommerce get-totals-for-checkout API endpoint returns unwanted data
Quick fix
GHSA-88g2-xgh9-4ph2 — oro/commerce: upgrade to the fixed version with the command below.
composer require oro/commerce:^5.0.11Details
Detailed Checkout totals information may be received by Checkout ID
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/oro/commerce
Introduced in:
4.2.0No fixed version published yet for oro/commerce (composer). Pin to a known-safe version or switch to an alternative.