Improper authorization control for web services In spree
Description
Spree does not properly restrict the use of a hash to provide values for a model's attributes Spree 0.2.0 does not properly restrict the use of a hash to provide values for a model's attributes, which allows remote attackers to set the Order state value and bypass the intended payment step via a modified URL, related to a "mass assignment" vulnerability.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
rubygems | 0.4.0 |
Aliases
1. 2. 3. 4.
References
1. 2. 3. 4. 5. 6.