icon

We found results for “

CVE-2020-15269

Good to know:

icon

Date: October 20, 2020

In Spree before versions 3.7.11, 4.0.4, or 4.1.11, expired user tokens could be used to access Storefront API v2 endpoints. The issue is patched in versions 3.7.11, 4.0.4 and 4.1.11. A workaround without upgrading is described in the linked advisory.

Language: Ruby

Severity Score

Severity Score

Weakness Type (CWE)

Authentication Issues

CWE-287

Insufficient Session Expiration

CWE-613

Top Fix

icon

Upgrade Version

Upgrade to version v3.7.11,v4.0.4,v4.1.11

Learn More

CVSS v3

Base Score:
Attack Vector (AV):
Attack Complexity (AC):
Privileges Required (PR):
User Interaction (UI):
Scope (S):
Confidentiality (C): COMPLETE
Integrity (I): COMPLETE
Availability (A): COMPLETE

CVSS v2

Base Score:
Access Vector (AV):
Access Complexity (AC):
Authentication (AU):
Confidentiality (C): LOW
Integrity (I): LOW
Availability (A): HIGH
Additional information:

Do you need more information?

Contact Us