VDB
Sign up
MEDIUM

GHSA-7h48-m3rw-vr27

Spree does not properly restrict the use of a hash to provide values for a model's attributes

Quick fix

GHSA-7h48-m3rw-vr27 — spree: upgrade to the fixed version with the command below.

bundle update spree

Details

Spree 0.2.0 does not properly restrict the use of a hash to provide values for a model's attributes, which allows remote attackers to set the Order state value and bypass the intended payment step via a modified URL, related to a "mass assignment" vulnerability.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/spree
Introduced in: 0Fixed in: 0.4.0
Fixbundle update spree

References