VDB
Sign up
MEDIUM

GHSA-jxx8-v83v-rhw3

Spree Improper Input Validation vulnerability

Quick fix

GHSA-jxx8-v83v-rhw3 — spree: upgrade to the fixed version with the command below.

bundle update spree

Details

Spree Commerce 1.0.x before 2.0.0.rc1 allows remote authenticated administrators to instantiate arbitrary Ruby objects and execute arbitrary commands via the (1) `payment_method` parameter to `core/app/controllers/spree/admin/payment_methods_controller.rb`; and the (2) `promotion_action parameter` to `promotion_actions_controller.rb`, (3) `promotion_rule parameter` to `promotion_rules_controller.rb`, and (4) `calculator_type` parameter to `promotions_controller.rb` in `promo/app/controllers/spree/admin/`, related to unsafe use of the constantize function.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/spree
Introduced in: 1.0.0Fixed in: 2.0.0.rc1
Fixbundle update spree

References