--- gem: spree cve: 2010-3978 osvdb: 69098 url: https://spreecommerce.com/blog/json-hijacking-vulnerability title: | Spree Multiple Script JSON Request Validation Weakness Remote Information Disclosure date: 2010-11-02 description: | Spree contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when the application exchanges data using the JSON service without validating requests, which will disclose sensitive user and order information to a context-dependent attacker when a logged-in user visits a crafted website. cvss_v2: 5.0 patched_versions: - ~> 0.11.2 - ">= 0.30.0"