GHSA-p6pv-q7rc-g4h9: Unauthenticated Spree Commerce users can view completed guest orders by Order ID
This issue may lead to disclosure of PII of guest users (including names, addresses and phone numbers).
References
- github.com/advisories/GHSA-p6pv-q7rc-g4h9
- github.com/spree/spree
- github.com/spree/spree/blob/1341623f2ae92685cdbe232885bf5808fc8f9ca8/storefront/app/controllers/spree/orders_controller.rb
- github.com/spree/spree/blob/1341623f2ae92685cdbe232885bf5808fc8f9ca8/storefront/app/controllers/spree/orders_controller.rb
- github.com/spree/spree/blob/a878eb4a782ce0445d218ea86fb12075b0e3d7cc/core/lib/spree/core/number_generator.rb
- github.com/spree/spree/commit/3e00be64c128ef4bd4b99731f0c3ab469509cfab
- github.com/spree/spree/commit/6b32ed7d474aa55fa441990e6aa39740152aa1be
- github.com/spree/spree/commit/6f6b8a7a28a8bff24a6e20eab04b4bbbdf39384d
- github.com/spree/spree/commit/ea4a5db590ca753dbc986f2a4e818d9e0edfb1ad
- github.com/spree/spree/security/advisories/GHSA-p6pv-q7rc-g4h9
Code Behaviors & Features
Detect and mitigate GHSA-p6pv-q7rc-g4h9 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →