MEDIUM
GHSA-jp57-9j37-5476
spree_auth_devise allows remote authenticated users to assign themselves arbitrary roles
Quick fix
GHSA-jp57-9j37-5476 — spree_auth_devise: upgrade to the fixed version with the command below.
bundle update spree_auth_deviseDetails
`app/models/spree/user.rb` in spree_auth_devise in Spree 1.1.x before 1.1.6, 1.2.x, and 1.3.x does not perform mass assignment safely when updating a user, which allows remote authenticated users to assign arbitrary roles to themselves.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2013-2506[ADVISORY]
- https://github.com/spree/spree_auth_devise/commit/038d74771d3b5c13d13b738b73dfda1033a99f65[WEB]
- https://github.com/spree/spree_auth_devise/commit/fda3ab9fb536c64fe18a9b78bb21c6176b3ea24d[WEB]
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/spree_auth/CVE-2013-2506.yml[WEB]
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/spree_auth_devise/CVE-2013-2506.yml[WEB]
- https://github.com/spree/spree_auth_devise[PACKAGE]
- https://web.archive.org/web/20131207040639/https://rubygems.org/gems/spree_auth_devise/versions[WEB]
- https://web.archive.org/web/20160331131233/https://spreecommerce.com/blog/multiple-security-vulnerabilities-fixed[WEB]