Vulnerabilities > CVE-2020-15269 - Insufficient Session Expiration vulnerability in Sparksolutions Spree
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
NONE Summary
In Spree before versions 3.7.11, 4.0.4, or 4.1.11, expired user tokens could be used to access Storefront API v2 endpoints. The issue is patched in versions 3.7.11, 4.0.4 and 4.1.11. A workaround without upgrading is described in the linked advisory.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |