In Spree before versions 3.7.11, 4.0.4, or 4.1.11, expired user tokens could be used to access Storefront API v2 endpoints. The issue is patched in versions 3.7.11, 4.0.4 and 4.1.11. A workaround without upgrading is described in the linked advisory.
{
"cpe": "cpe:2.3:a:sparksolutions:spree:*:*:*:*:*:*:*:*",
"source": [
"CPE_RANGE",
"REFERENCES"
],
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "3.7.11"
},
{
"introduced": "4.0.0"
},
{
"fixed": "4.0.4"
},
{
"introduced": "4.1.0"
},
{
"fixed": "4.1.11"
}
]
}