CVE-2020-26223

HIGH7.7EPSS 0.27%

Authorization bypass in Spree

發布日:2020/11/13修改日:2026/3/13

描述

### Impact The perpetrator could query the [API v2 Order Status](https://guides.spreecommerce.org/api/v2/storefront#tag/Order-Status) endpoint with an empty string passed as an Order token ### Patches Please upgrade to 3.7.11, 4.0.4, or 4.1.11 depending on your used Spree version. Users of Spree < 3.7 are not affected. ### References Pull request with a fix and in-depth explanation - https://github.com/spree/spree/pull/10573 ### For more information If you have any questions or comments about this advisory: * Email us at [[email protected]](mailto:[email protected])

受影響套件(1)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1HIGH7.7CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

參考連結(7)