Sha256: f778c095bdaffd957ed9ea30e055dfa9643ff590a51148f13ef185e754c9ab02

Contents?: true

Size: 534 Bytes

Versions: 6

Compression:

Stored size: 534 Bytes

Contents

---
gem: spree
osvdb: 125699
url: https://spreecommerce.com/blog/security-updates-2015-7-28
title: |
  Spree RABL templates rendering allows Arbitrary Code Execution and File
  Disclosure
date: 2015-07-28
description: |
  Spree contains a flaw where the rendering of arbitrary RABL templates allows
  for execution arbitrary files on the host system, as well as disclosing the
  existence of files on the system. This is a different issue than
  OSVDB-125701.
patched_versions:
  - ~> 2.2.13
  - ~> 2.3.12
  - ~> 2.4.9
  - ">= 3.0.3"

Version data entries

6 entries across 6 versions & 2 rubygems

Version Path
bundler-audit-0.7.0.1 data/ruby-advisory-db/gems/spree/OSVDB-125699.yml
bundler-budit-0.6.2 data/ruby-advisory-db/gems/spree/OSVDB-125699.yml
bundler-budit-0.6.1 data/ruby-advisory-db/gems/spree/OSVDB-125699.yml
bundler-audit-0.6.1 data/ruby-advisory-db/gems/spree/OSVDB-125699.yml
bundler-audit-0.6.0 data/ruby-advisory-db/gems/spree/OSVDB-125699.yml
bundler-audit-0.5.0 data/ruby-advisory-db/gems/spree/OSVDB-125699.yml