File tree Expand file tree Collapse file tree 1 file changed +9
-4
lines changed Expand file tree Collapse file tree 1 file changed +9
-4
lines changed Original file line number Diff line number Diff line change 22gem : spree
33cve : 2013-1656
44ghsa : jxx8-v83v-rhw3
5- url : https://blog.convisoappsec. com/en/spree-commerce-multiple-unsafe-reflection-vulnerabilities-cve-2013-1656
5+ url : https://github. com/advisories/GHSA-jxx8-v83v-rhw3
66title : Spree controller Parameter Arbitrary Ruby Object Instantiation Command Execution
77date : 2013-02-21
88description : |
9- Spree Commerce 1.0.x through 1.3.2 allows remote authenticated
9+ Spree Commerce 1.0.x before 2.0.0.rc1 allows remote authenticated
1010 administrators to instantiate arbitrary Ruby objects and executd
1111 arbitrary commands via the
1212 (1) payment_method parameter to core/app/controllers/spree/admin/
@@ -18,7 +18,12 @@ description: |
1818 of the constantize function.
1919cvss_v2 : 4.3
2020patched_versions :
21- - " >= 2.0.0"
21+ - " >= 2.0.0.rc1 "
2222related :
2323 url :
24- - https://spreecommerce.com/blog/multiple-security-vulnerabilities-fixed
24+ - https://nvd.nist.gov/vuln/detail/CVE-2013-1656
25+ - https://github.com/spree/spree/commit/70092eb55b8be8fe5d21a7658b62da658612fba7
26+ - https://web.archive.org/web/20130907044454/https://www.conviso.com.br/advisories/CVE-2013-1656.txt
27+ - https://web.archive.org/web/20140329142330/http://spreecommerce.com/blog/multiple-security-vulnerabilities-fixed
28+ - https://web.archive.org/web/20140618100330/http://blog.conviso.com.br/2013/03/spree-commerce-multiple-unsafe.html
29+ - https://github.com/advisories/GHSA-jxx8-v83v-rhw3
You can’t perform that action at this time.
0 commit comments