A vulnerability affecting spree_api versions >= 5.4.0, < 5.4.4 affecting spree_api versions >= 5.5.0, < 5.5.4 in the Spree e-commerce platform allows an authenticated attacker to enumerate guest cart IDs and read checkout PII on carts they don't own. The flaw, which affects versions 5.4.0 to 5.4.3 and 5.5.0 to 5.5.3, is due to a missing authorization check in the method responsible for finding carts by association. An attacker can exploit this vulnerability by deriving candidate IDs offline using an encoding algorithm and then attempting to associate them with their own cart via a specific endpoint. If successful, they will receive the victim's billing address or shipping address in response. This vulnerability has a high severity rating due to its potential impact on confidentiality and integrity, but it is not anonymously exploitable since the attacker requires a registered account in order to exploit it. The attack involves deriving candidate IDs offline using an encoding algorithm, attempting to associate them with their own cart via a specific endpoint, and receiving the victim's billing address or shipping address in response.
We recommend you to update Spree to version 5.4.4 or 5.5.4.[/subscribe_to_unlock_form]
A vulnerability affecting spree_api versions >= 5.4.0, < 5.4.4 affecting spree_api versions >= 5.5.0, < 5.5.4 in the Spree e-commerce platform allows an authenticated attacker to enumerate guest cart IDs and read checkout PII on carts they don't own. The flaw, which affects versions 5.4.0 to 5.4.3 and 5.5.0 to 5.5.3, is due to a missing authorization check in the method responsible for finding carts by association. An attacker can exploit this vulnerability by deriving candidate IDs offline using an encoding algorithm and then attempting to associate them with their own cart via a specific endpoint. If successful, they will receive the victim's billing address or shipping address in response. This vulnerability has a high severity rating due to its potential impact on confidentiality and integrity, but it is not anonymously exploitable since the attacker requires a registered account in order to exploit it. The attack involves deriving candidate IDs offline using an encoding algorithm, attempting to associate them with their own cart via a specific endpoint, and receiving the victim's billing address or shipping address in response.
We recommend you to update Spree to version 5.4.4 or 5.5.4.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]