Логотип exploitDog
bind:CVE-2026-22589
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2026-22589

Количество 2

Количество 2

nvd логотип

CVE-2026-22589

10 дней назад

Spree is an open source e-commerce solution built with Ruby on Rails. Prior to versions 4.10.2, 5.0.7, 5.1.9, and 5.2.5, an Unauthenticated Insecure Direct Object Reference (IDOR) vulnerability was identified that allows an unauthenticated attacker to access guest address information without supplying valid credentials or session cookies. This issue has been patched in versions 4.10.2, 5.0.7, 5.1.9, and 5.2.5.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3ghg-3787-w2xr

12 дней назад

Spree API has Unauthenticated IDOR - Guest Address

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-22589

Spree is an open source e-commerce solution built with Ruby on Rails. Prior to versions 4.10.2, 5.0.7, 5.1.9, and 5.2.5, an Unauthenticated Insecure Direct Object Reference (IDOR) vulnerability was identified that allows an unauthenticated attacker to access guest address information without supplying valid credentials or session cookies. This issue has been patched in versions 4.10.2, 5.0.7, 5.1.9, and 5.2.5.

CVSS3: 7.5
0%
Низкий
10 дней назад
github логотип
GHSA-3ghg-3787-w2xr

Spree API has Unauthenticated IDOR - Guest Address

CVSS3: 7.5
0%
Низкий
12 дней назад

Уязвимостей на страницу