CVE-2020-26223 Information
Jun 07, 2022
cve
Description
Spree is a complete open source e-commerce solution built with Ruby on Rails. In Spree from version 3.7 and before versions 3.7.13 4.0.5 and 4.1.12 there is an authorization bypass vulnerability. The perpetrator could query the API v2 Order Status endpoint with an empty string passed as an Order token. This is patched in versions 3.7.11 4.0.4 or 4.1.11 depending on your used Spree version. Users of Spree < 3.7 are not affected.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Reference
https://github.com/spree/spree/pull/10573 https://github.com/spree/spree/security/advisories/GHSA-m2jr-hmc3-qmpr https://guides.spreecommerce.org/api/v2/storefront#tag/Order-Status
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
NONE
Base Score
NONE
Base Severity
6.5
Share on: