Sha256: 2d7d5c4b32e10859e10ab6619a3935e0a7302c0b1153f95d80ff112d0b511517

Contents?: true

Size: 636 Bytes

Versions: 6

Compression:

Stored size: 636 Bytes

Contents

---
gem: spree
cve: 2010-3978
osvdb: 69098
url: https://spreecommerce.com/blog/json-hijacking-vulnerability
title: |
  Spree Multiple Script JSON Request Validation Weakness Remote Information
  Disclosure
date: 2010-11-02
description: |
  Spree contains a flaw that may lead to an unauthorized information
  disclosure. The issue is triggered when the application exchanges data using
  the JSON service without validating requests, which will disclose sensitive
  user and order information to a context-dependent attacker when a logged-in
  user visits a crafted website.
cvss_v2: 5.0
patched_versions:
  - ~> 0.11.2
  - ">= 0.30.0"

Version data entries

6 entries across 6 versions & 2 rubygems

Version Path
bundler-audit-0.7.0.1 data/ruby-advisory-db/gems/spree/OSVDB-69098.yml
bundler-budit-0.6.2 data/ruby-advisory-db/gems/spree/OSVDB-69098.yml
bundler-budit-0.6.1 data/ruby-advisory-db/gems/spree/OSVDB-69098.yml
bundler-audit-0.6.1 data/ruby-advisory-db/gems/spree/OSVDB-69098.yml
bundler-audit-0.6.0 data/ruby-advisory-db/gems/spree/OSVDB-69098.yml
bundler-audit-0.5.0 data/ruby-advisory-db/gems/spree/OSVDB-69098.yml