UNKNOWN RubyGems
spree_auth_devise allows remote authenticated users to assign themselves arbitrary roles
GHSA-jp57-9j37-5476 · CVE-2013-2506
Published · Modified
Description
app/models/spree/user.rb in spree_auth_devise in Spree 1.1.x before 1.1.6, 1.2.x, and 1.3.x does not perform mass assignment safely when updating a user, which allows remote authenticated users to assign arbitrary roles to themselves.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2013-2506
- WEB https://github.com/spree/spree_auth_devise/commit/038d74771d3b5c13d13b738b73dfda1033a99f65
- WEB https://github.com/spree/spree_auth_devise/commit/fda3ab9fb536c64fe18a9b78bb21c6176b3ea24d
- WEB https://github.com/rubysec/ruby-advisory-db/blob/master/gems/spree_auth/CVE-2013-2506.yml
- WEB https://github.com/rubysec/ruby-advisory-db/blob/master/gems/spree_auth_devise/CVE-2013-2506.yml
- PACKAGE https://github.com/spree/spree_auth_devise
- WEB https://web.archive.org/web/20131207040639/https://rubygems.org/gems/spree_auth_devise/versions
- WEB https://web.archive.org/web/20160331131233/https://spreecommerce.com/blog/multiple-security-vulnerabilities-fixed
Ready to move
Start Securing
Free, no credit card | First findings in minutes