Vulnerabilities > CVE-2020-15269 - Insufficient Session Expiration vulnerability in Sparksolutions Spree
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
NONE Summary
In Spree before versions 3.7.11, 4.0.4, or 4.1.11, expired user tokens could be used to access Storefront API v2 endpoints. The issue is patched in versions 3.7.11, 4.0.4 and 4.1.11. A workaround without upgrading is described in the linked advisory.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |