Логотип exploitDog
bind:CVE-2020-26223
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-26223

Количество 2

Количество 2

nvd логотип

CVE-2020-26223

около 5 лет назад

Spree is a complete open source e-commerce solution built with Ruby on Rails. In Spree from version 3.7 and before versions 3.7.13, 4.0.5, and 4.1.12, there is an authorization bypass vulnerability. The perpetrator could query the API v2 Order Status endpoint with an empty string passed as an Order token. This is patched in versions 3.7.11, 4.0.4, or 4.1.11 depending on your used Spree version. Users of Spree < 3.7 are not affected.

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-m2jr-hmc3-qmpr

около 5 лет назад

Authorization bypass in Spree

CVSS3: 7.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-26223

Spree is a complete open source e-commerce solution built with Ruby on Rails. In Spree from version 3.7 and before versions 3.7.13, 4.0.5, and 4.1.12, there is an authorization bypass vulnerability. The perpetrator could query the API v2 Order Status endpoint with an empty string passed as an Order token. This is patched in versions 3.7.11, 4.0.4, or 4.1.11 depending on your used Spree version. Users of Spree < 3.7 are not affected.

CVSS3: 7.7
0%
Низкий
около 5 лет назад
github логотип
GHSA-m2jr-hmc3-qmpr

Authorization bypass in Spree

CVSS3: 7.7
0%
Низкий
около 5 лет назад

Уязвимостей на страницу