VDB
Sign up
MEDIUM

GHSA-jp57-9j37-5476

spree_auth_devise allows remote authenticated users to assign themselves arbitrary roles

Quick fix

GHSA-jp57-9j37-5476 — spree_auth_devise: upgrade to the fixed version with the command below.

bundle update spree_auth_devise

Details

`app/models/spree/user.rb` in spree_auth_devise in Spree 1.1.x before 1.1.6, 1.2.x, and 1.3.x does not perform mass assignment safely when updating a user, which allows remote authenticated users to assign arbitrary roles to themselves.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/spree_auth_devise
Introduced in: 1.0.0Fixed in: 3.0.5
Fixbundle update spree_auth_devise

References