VDB
Sign up
MEDIUM

GHSA-hwrx-wc75-mgh7

Spree allows remote attackers to obtain sensitive information

Quick fix

GHSA-hwrx-wc75-mgh7 — spree: upgrade to the fixed version with the command below.

bundle update spree

Details

Spree 0.11.x before 0.11.2 and 0.30.x before 0.30.0 exchanges data using JavaScript Object Notation (JSON) without a mechanism for validating requests, which allows remote attackers to obtain sensitive information via vectors involving (1) `admin/products.json`, (2) `admin/users.json`, or (3) `admin/overview/get_report_data`, related to a "JSON hijacking" issue.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/spree
Introduced in: 0.11.0Fixed in: 0.11.2
Fixbundle update spree
RubyGems/spree
Introduced in: 0.30.0.beta1Fixed in: 0.30.0
Fixbundle update spree

References