CVE-2020-15269

Source
https://cve.org/CVERecord?id=CVE-2020-15269
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-15269.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2020-15269
Aliases
Published
2020-10-20T21:15:12.743Z
Modified
2026-07-09T02:49:35.915564Z
Severity
  • 9.1 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N CVSS Calculator
Summary
[none]
Details

In Spree before versions 3.7.11, 4.0.4, or 4.1.11, expired user tokens could be used to access Storefront API v2 endpoints. The issue is patched in versions 3.7.11, 4.0.4 and 4.1.11. A workaround without upgrading is described in the linked advisory.

References

Affected packages

Git / github.com/spree/spree

Affected ranges

Type
GIT
Repo
https://github.com/spree/spree
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:sparksolutions:spree:*:*:*:*:*:*:*:*",
    "source": [
        "CPE_RANGE",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "3.7.11"
        },
        {
            "introduced": "4.0.0"
        },
        {
            "fixed": "4.0.4"
        },
        {
            "introduced": "4.1.0"
        },
        {
            "fixed": "4.1.11"
        }
    ]
}

Affected versions

v0.*
v0.11.0
v0.11.99
v0.2.0
v0.30.0.beta1
v0.4.0
v0.40.0
v0.70.0.rc2
v0.8.2
v1.*
v1.0.0.rc1
v1.0.0.rc2
v1.0.0.rc3
v1.2.0.rc1
v2.*
v2.4.0.rc1
v2.4.0.rc2
v3.*
v3.0.0.rc1
v3.1.0.rc1
v3.2.0.rc1
v3.2.2
v3.3.0
v3.3.0.rc1
v3.3.0.rc2
v3.3.0.rc3
v3.3.0.rc4
v3.4.0
v3.4.0.rc1
v3.4.0.rc2
v3.5.0.rc1
v3.6.0.rc1
v3.7.0
v3.7.0.beta
v3.7.0.rc1
v3.7.0.rc2
v3.7.0.rc3
v3.7.1
v3.7.10
v3.7.2
v3.7.3
v3.7.4
v3.7.5
v3.7.6
v3.7.8
v3.7.9
v4.*
v4.0.0
v4.0.1
v4.0.2
v4.0.3
v4.1.0
v4.1.1
v4.1.10
v4.1.2
v4.1.3
v4.1.4
v4.1.5
v4.1.6
v4.1.7
v4.1.8
v4.1.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-15269.json"