Spree Multiple Script JSON Request Validation Weakness Remote Information Disclosure
Published: November 02, 2010
SECURITY IDENTIFIERS
- CVE: CVE-2010-3978 (NVD)
- GHSA: GHSA-hwrx-wc75-mgh7
- OSVDB: OSVDB-69098
- Vendor Advisory: https://spreecommerce.com/blog/json-hijacking-vulnerability
GEM
SEVERITY
CVSS v2.0: 5.0 (Medium)
PATCHED VERSIONS
~> 0.11.2
>= 0.30.0
DESCRIPTION
Spree contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when the application exchanges data using the JSON service without validating requests, which will disclose sensitive user and order information to a context-dependent attacker when a logged-in user visits a crafted website.
