Skip to content
Closed
Changes from 1 commit
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions gems/spree/CVE-2013-1656.yml
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ url: https://blog.convisoappsec.com/en/spree-commerce-multiple-unsafe-reflection
title: Spree controller Parameter Arbitrary Ruby Object Instantiation Command Execution
date: 2013-02-21
description: |
Spree Commerce 1.0.x through 1.3.2 allows remote authenticated
Spree Commerce 1.0.x before 2.0.0.rc1 allows remote authenticated
administrators to instantiate arbitrary Ruby objects and executd
arbitrary commands via the
(1) payment_method parameter to core/app/controllers/spree/admin/
Expand All @@ -18,7 +18,7 @@ description: |
of the constantize function.
cvss_v2: 4.3
patched_versions:
- ">= 2.0.0"
- ">= 2.0.0.rc1"
related:
url:
- https://spreecommerce.com/blog/multiple-security-vulnerabilities-fixed