Описание
spree_auth_devise allows remote authenticated users to assign themselves arbitrary roles
app/models/spree/user.rb in spree_auth_devise in Spree 1.1.x before 1.1.6, 1.2.x, and 1.3.x does not perform mass assignment safely when updating a user, which allows remote authenticated users to assign arbitrary roles to themselves.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2013-2506
- https://github.com/spree/spree_auth_devise/commit/038d74771d3b5c13d13b738b73dfda1033a99f65
- https://github.com/spree/spree_auth_devise/commit/fda3ab9fb536c64fe18a9b78bb21c6176b3ea24d
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/spree_auth/CVE-2013-2506.yml
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/spree_auth_devise/CVE-2013-2506.yml
- https://web.archive.org/web/20131207040639/https://rubygems.org/gems/spree_auth_devise/versions
- https://web.archive.org/web/20160331131233/https://spreecommerce.com/blog/multiple-security-vulnerabilities-fixed
Пакеты
Наименование
spree_auth_devise
rubygems
Затронутые версииВерсия исправления
>= 1.0.0, < 3.0.5
3.0.5
EPSS
Процентиль: 39%
0.00171
Низкий
CVE ID
Связанные уязвимости
nvd
почти 13 лет назад
app/models/spree/user.rb in spree_auth_devise in Spree 1.1.x before 1.1.6, 1.2.x, and 1.3.x does not perform mass assignment safely when updating a user, which allows remote authenticated users to assign arbitrary roles to themselves.
EPSS
Процентиль: 39%
0.00171
Низкий