Sha256: e4ef7a9b081409b5bbd377b539954085caf07ea555b7b372a8c84d50a2832bb9
Contents?: true
Size: 611 Bytes
Versions: 6
Compression:
Stored size: 611 Bytes
Contents
--- gem: spree_auth cve: 2013-2506 osvdb: 90865 url: https://spreecommerce.com/blog/multiple-security-vulnerabilities-fixed title: | Spree app/models/spree/user.rb Mass Role Assignment Remote Privilege Escalation date: 2013-02-21 description: | Spree contains a flaw that leads to unauthorized privileges being gained. The issue is triggered as certain input related to mass role assignment in app/models/spree/user.rb is not properly verified before being used to update a user. This may allow a remote attacker to assign arbitrary roles and gain elevated administrative privileges. cvss_v2: 4.0
Version data entries
6 entries across 6 versions & 2 rubygems