RubySec

Providing security resources for the Ruby community

OSVDB-125701 (spree): Spree RABL templates rendering allows Arbitrary Code Execution and File Disclosure

ADVISORIES

GEM

spree

PATCHED VERSIONS

  • ~> 2.2.12
  • ~> 2.3.11
  • ~> 2.4.8
  • >= 3.0.2

DESCRIPTION

Spree contains a flaw where the rendering of arbitrary RABL templates allows for execution arbitrary files on the host system, as well as disclosing the existence of files on the system.

RELATED