Arbitrary Command Execution Affecting spree package, versions < 1.1.2, >= 1.1 < 1.0.5, >= 0.71 < 0.70.6, >= 0.12 < 0.11.4
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-RUBY-SPREE-20034
- published 1 Jul 2012
- disclosed 1 Jul 2012
- credit joernchen
Overview
Spree
is an open source e-commerce framework for Ruby on Rails.
Product Scopes could allow for unauthenticated remote command execution. This was corrected by removing conditions_any scope and use ARel query building instead.
CVSS Scores
version 3.1