Sha256: 093b6fa6c3b0e86b390076e9d279fab4effe4d25d91efe15c57dcd931de2419b
Contents?: true
Size: 665 Bytes
Versions: 6
Compression:
Stored size: 665 Bytes
Contents
--- gem: spree cve: 2013-2506 osvdb: 90865 url: https://spreecommerce.com/blog/multiple-security-vulnerabilities-fixed title: | Spree app/models/spree/user.rb Mass Role Assignment Remote Privilege Escalation date: 2013-02-21 description: | Spree contains a flaw that leads to unauthorized privileges being gained. The issue is triggered as certain input related to mass role assignment in app/models/spree/user.rb is not properly verified before being used to update a user. This may allow a remote attacker to assign arbitrary roles and gain elevated administrative privileges. cvss_v2: 4.0 patched_versions: - ~> 1.1.6 - ~> 1.2.0 - ">= 1.3.0"
Version data entries
6 entries across 6 versions & 2 rubygems