CVE-2013-1656
Spree Improper Input Validation vulnerability
EPSS 1.5%
描述
Spree Commerce 1.0.x before 2.0.0.rc1 allows remote authenticated administrators to instantiate arbitrary Ruby objects and execute arbitrary commands via the (1) `payment_method` parameter to `core/app/controllers/spree/admin/payment_methods_controller.rb`; and the (2) `promotion_action parameter` to `promotion_actions_controller.rb`, (3) `promotion_rule parameter` to `promotion_rules_controller.rb`, and (4) `calculator_type` parameter to `promotions_controller.rb` in `promo/app/controllers/spree/admin/`, related to unsafe use of the constantize function.
如何修補 CVE-2013-1656
要修補 CVE-2013-1656,請將受影響套件升級到下列已修補版本。
- —升級至 2.0.0.rc1 或更新版本
CVE-2013-1656 正在被利用嗎?
低 — EPSS 為 1.5%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- >= 1.0.0, < 2.0.0.rc1