Spree API has Unauthenticated IDOR - Guest Address
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.5epss 0.4%
exploitation probability
0.4%top 68% of all CVEs
observed exploitation
nono source reports it
Spree is an open source e-commerce solution built with Ruby on Rails. Prior to versions 4.10.2, 5.0.7, 5.1.9, and 5.2.5, an Unauthenticated Insecure Direct Object Reference (IDOR) vulnerability was identified that allows an unauthenticated attacker to access guest address information without supplying valid credentials or session cookies. This issue has been patched in versions 4.10.2, 5.0.7, 5.1.9, and 5.2.5.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected products
spree · spreeReferences
https://github.com/spree/spree/commit/16067def6de8e0742d55313e83b0fbab6d2fd795https://github.com/spree/spree/commit/4c2bd62326fba0d846fd9e4bad2c62433829b3adhttps://github.com/spree/spree/commit/d051925778f24436b62fa8e4a6b842c72ca80a67https://github.com/spree/spree/commit/e1cff4605eb15472904602aebaf8f2d04852d6adhttps://github.com/spree/spree/security/advisories/GHSA-3ghg-3787-w2xr