Expired token reuse in Spree
CVE-2020-15269
7.4HIGH
What is CVE-2020-15269?
In Spree before versions 3.7.11, 4.0.4, or 4.1.11, expired user tokens could be used to access Storefront API v2 endpoints. The issue is patched in versions 3.7.11, 4.0.4 and 4.1.11. A workaround without upgrading is described in the linked advisory.
Affected Version(s)
spree < 3.7.11 < 3.7.11
spree >= 4.0.0, < 4.0.4 < 4.0.0, 4.0.4
spree >= 4.1.0, < 4.1.11 < 4.1.0, 4.1.11
