Description
In Spree before versions 3.7.11, 4.0.4, or 4.1.11, expired user tokens could be used to access Storefront API v2 endpoints. The issue is patched in versions 3.7.11, 4.0.4 and 4.1.11. A workaround without upgrading is described in the linked advisory.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-1427 | In Spree before versions 3.7.11, 4.0.4, or 4.1.11, expired user tokens could be used to access Storefront API v2 endpoints. The issue is patched in versions 3.7.11, 4.0.4 and 4.1.11. A workaround without upgrading is described in the linked advisory. |
Github GHSA |
GHSA-f8cm-364f-q9qh | Ensure that doorkeeper_token is valid when authenticating requests in API v2 calls |
References
History
No history.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-04T13:15:18.944Z
Reserved: 2020-06-25T00:00:00.000Z
Link: CVE-2020-15269
No data.
Status : Modified
Published: 2020-10-20T21:15:12.743
Modified: 2024-11-21T05:05:14.067
Link: CVE-2020-15269
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA