Authorization bypass in Spree
CVE-2020-26223

7.7HIGH

Key Information:

Vendor

Spree

Status
Vendor
CVE Published:
13 November 2020

What is CVE-2020-26223?

Spree is a complete open source e-commerce solution built with Ruby on Rails. In Spree from version 3.7 and before versions 3.7.13, 4.0.5, and 4.1.12, there is an authorization bypass vulnerability. The perpetrator could query the API v2 Order Status endpoint with an empty string passed as an Order token. This is patched in versions 3.7.11, 4.0.4, or 4.1.11 depending on your used Spree version. Users of Spree < 3.7 are not affected.

Affected Version(s)

spree >= 3.7.0, < 3.7.13 < 3.7.0, 3.7.13

spree >= 4.0.0, < 4.0.5 < 4.0.0, 4.0.5

spree >= 4.1.0, < 4.1.12 < 4.1.0, 4.1.12

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.