VDB
Sign up
MEDIUM

GHSA-g466-57gh-cqfw

Spree uses a hardcoded hash value

Quick fix

GHSA-g466-57gh-cqfw — spree: upgrade to the fixed version with the command below.

bundle update spree

Details

The session cookie store implementation in Spree 0.2.0 uses a hardcoded `config.action_controller_session` hash value (aka secret key), which makes it easier for remote attackers to bypass cryptographic protection mechanisms by leveraging an application that contains this value within the `config/environment.rb` file.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/spree
Introduced in: 0Fixed in: 0.4.0
Fixbundle update spree

References