MidnightBSD

Advisories for spreecommerce

CVE-2008-7310 MEDIUM

Spree 0.2.0 does not properly restrict the use of a hash to provide values for a model's attributes, which allows remote attackers to set the Order state value and bypass the intended payment step via a modified URL, related to a "mass assignment" vulnerability.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-255,

Products Affected

Vendor Product Version
spreecommerce spree 0.2.0
CVE-2008-7311 MEDIUM

The session cookie store implementation in Spree 0.2.0 uses a hardcoded config.action_controller_session hash value (aka secret key), which makes it easier for remote attackers to bypass cryptographic protection mechanisms by leveraging an application that contains this value within the config/environment.rb file.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-255,

Products Affected

Vendor Product Version
spreecommerce spree 0.2.0
CVE-2010-3978 MEDIUM

Spree 0.11.x before 0.11.2 and 0.30.x before 0.30.0 exchanges data using JavaScript Object Notation (JSON) without a mechanism for validating requests, which allows remote attackers to obtain sensitive information via vectors involving (1) admin/products.json, (2) admin/users.json, or (3) admin/overview/get_report_data, related to a "JSON hijacking" issue.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
spreecommerce spree 0.30.0
spreecommerce spree 0.11.0
spreecommerce spree 0.11.1
CVE-2013-1656 MEDIUM

Spree Commerce 1.0.x through 1.3.2 allows remote authenticated administrators to instantiate arbitrary Ruby objects and execute arbitrary commands via the (1) payment_method parameter to core/app/controllers/spree/admin/payment_methods_controller.rb; and the (2) promotion_action parameter to promotion_actions_controller.rb, (3) promotion_rule parameter to promotion_rules_controller.rb, and (4) calculator_type parameter to promotions_controller.rb in promo/app/controllers/spree/admin/, related to unsafe use of the constantize function.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
spreecommerce spree 1.0.3
spreecommerce spree 1.1.4
spreecommerce spree 1.1.5
spreecommerce spree 1.2.2
spreecommerce spree 1.1.3
spreecommerce spree 1.3.1
spreecommerce spree 1.0.4
spreecommerce spree 1.0.7
spreecommerce spree 1.0.2
spreecommerce spree 1.2.0
spreecommerce spree 1.2.4
spreecommerce spree 1.1.1
spreecommerce spree 1.3.0
spreecommerce spree 1.2.3
spreecommerce spree 1.2.1
spreecommerce spree 1.0.0
spreecommerce spree 1.1.6
spreecommerce spree 1.0.1
spreecommerce spree 1.0.5
spreecommerce spree 1.1.0
spreecommerce spree 1.0.6
spreecommerce spree *
spreecommerce spree 1.1.2
CVE-2013-2506 MEDIUM

app/models/spree/user.rb in spree_auth_devise in Spree 1.1.x before 1.1.6, 1.2.x, and 1.3.x does not perform mass assignment safely when updating a user, which allows remote authenticated users to assign arbitrary roles to themselves.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
spreecommerce spree 1.1.4
spreecommerce spree 1.1.5
spreecommerce spree 1.2.2
spreecommerce spree 1.1.3
spreecommerce spree 1.3.1
spreecommerce spree 1.3.2
spreecommerce spree 1.2.0
spreecommerce spree 1.2.4
spreecommerce spree 1.1.1
spreecommerce spree 1.3.0
spreecommerce spree 1.2.3
spreecommerce spree 1.2.1
spreecommerce spree 1.1.6
spreecommerce spree 1.1.0
spreecommerce spree 1.1.2