VDB
Sign up
CRITICAL

GHSA-x485-rhg3-cqr4

Spree Commerce is vulnerable to RCE through Search API

Quick fix

GHSA-x485-rhg3-cqr4 — spree: upgrade to the fixed version with the command below.

bundle update spree

Details

Spreecommerce versions prior to 0.50.x contain a remote command execution vulnerability in the API's search functionality. Improper input sanitation allows attackers to inject arbitrary shell commands via the search[instance_eval] parameter, which is dynamically invoked using Ruby’s send method. This flaw enables unauthenticated attackers to execute commands on the server.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/spree
Introduced in: 0.30.0.beta1Fixed in: 0.50.0
Fixbundle update spree
RubyGems/rd_searchlogic
Introduced in: 0

No fixed version published yet for rd_searchlogic (bundler). Pin to a known-safe version or switch to an alternative.

References