CRITICAL
GHSA-x485-rhg3-cqr4
Spree Commerce is vulnerable to RCE through Search API
Quick fix
GHSA-x485-rhg3-cqr4 — spree: upgrade to the fixed version with the command below.
bundle update spreeDetails
Spreecommerce versions prior to 0.50.x contain a remote command execution vulnerability in the API's search functionality. Improper input sanitation allows attackers to inject arbitrary shell commands via the search[instance_eval] parameter, which is dynamically invoked using Ruby’s send method. This flaw enables unauthenticated attackers to execute commands on the server.
Are you affected?
Enter the version of the package you're using.
Affected packages
RubyGems/rd_searchlogic
Introduced in:
0No fixed version published yet for rd_searchlogic (bundler). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2011-10026[ADVISORY]
- https://github.com/spree/spree/commit/0a9a360c590829d8a377ceae0cf997bbbbcc2df4[WEB]
- https://github.com/spree/spree/commit/3b559e7219f3681184be409ad00cd34a34a37978[WEB]
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/rd_searchlogic/CVE-2011-10026.yml[WEB]
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/spree/CVE-2011-10026.yml[WEB]
- https://github.com/spree[WEB]
- https://github.com/spree/spree[PACKAGE]
- https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/multi/http/spree_searchlogic_exec.rb[WEB]
- https://web.archive.org/web/20111120023342/http://spreecommerce.com/blog/2011/04/19/security-fixes[WEB]
- https://www.exploit-db.com/exploits/17199[WEB]
- https://www.vulncheck.com/advisories/spreecommerce-api-rce[WEB]