HIGH🇵🇱 Wersja polska

CVE-2020-26223

CVSS 7.7v3.1pub. 2020-11-13upd. 2024-11-21

Spree is a complete open source e-commerce solution built with Ruby on Rails. In Spree from version 3.7 and before versions 3.7.13, 4.0.5, and 4.1.12, there is an authorization bypass vulnerability. The perpetrator could query the API v2 Order Status endpoint with an empty string passed as an Order token. This is patched in versions 3.7.11, 4.0.4, or 4.1.11 depending on your used Spree version. Users of Spree < 3.7 are not affected.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
  • Spreecommerce Spree

    APP
    Spreecommerce
    3.7.0 – 3.7.13 (excl.)4.0.0 – 4.0.5 (excl.)4.1.0 – 4.1.12 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2011-10026CRITICAL9.3PL ✓same product

RCE via command injection w API wyszukiwania Spreecommerce Spree

CVE-2011-10019CRITICAL10.0PL ✓same product

RCE w Spreecommerce Spree — brak sanitizacji parametru wyszukiwania

CVE-2026-25758HIGH7.7same product

Spree is an open source e-commerce solution built with Ruby on Rails. A critical IDOR vulnerability exists in ...

CVE-2026-25757HIGH7.7same product

Spree is an open source e-commerce solution built with Ruby on Rails. Prior to versions 5.0.8, 5.1.10, 5.2.7, ...

CVE-2026-22589HIGH7.5same product

Spree is an open source e-commerce solution built with Ruby on Rails. Prior to versions 4.10.2, 5.0.7, 5.1.9, ...