CVE-2020-15269
—CVSS 3.1
9.1 critical
EPSS
1%p63
Published
()
Modified
Description
In Spree before versions 3.7.11, 4.0.4, or 4.1.11, expired user tokens could be used to access Storefront API v2 endpoints. The issue is patched in versions 3.7.11, 4.0.4 and 4.1.11. A workaround without upgrading is described in the linked advisory.
- Vendors
- sparksolutions
- Products
- spree
- Weakness
- CWE-287, CWE-613
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.