ADVISORIES
GEM
SEVERITY
CVSS v3.x: 7.4 (High)
UNAFFECTED VERSIONS
- < 3.7.0
PATCHED VERSIONS
- ~> 3.7.11
- ~> 4.0.4
- >= 4.1.11
DESCRIPTION
Impact
The perpetrator who previously obtained an old expired user token could use it to access Storefront API v2 endpoints.
Patches
Please upgrade to 3.7.11, 4.0.4, or 4.1.11 depending on your used Spree version.