Expired token reuse in Spree
CVE-2020-15269

7.4HIGH

Key Information:

Vendor

Spree

Status
Vendor
CVE Published:
20 October 2020

What is CVE-2020-15269?

In Spree before versions 3.7.11, 4.0.4, or 4.1.11, expired user tokens could be used to access Storefront API v2 endpoints. The issue is patched in versions 3.7.11, 4.0.4 and 4.1.11. A workaround without upgrading is described in the linked advisory.

Affected Version(s)

spree < 3.7.11 < 3.7.11

spree >= 4.0.0, < 4.0.4 < 4.0.0, 4.0.4

spree >= 4.1.0, < 4.1.11 < 4.1.0, 4.1.11

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.