{"id":"CVE-2020-15269","details":"In Spree before versions 3.7.11, 4.0.4, or 4.1.11, expired user tokens could be used to access Storefront API v2 endpoints. The issue is patched in versions 3.7.11, 4.0.4 and 4.1.11. A workaround without upgrading is described in the linked advisory.","aliases":["GHSA-f8cm-364f-q9qh"],"modified":"2026-07-09T02:49:35.915564Z","published":"2020-10-20T21:15:12.743Z","references":[{"type":"ADVISORY","url":"https://github.com/spree/spree/security/advisories/GHSA-f8cm-364f-q9qh"},{"type":"FIX","url":"https://github.com/spree/spree/commit/e43643abfe51f54bd9208dd02298b366e9b9a847"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/spree/spree","events":[{"introduced":"0"},{"fixed":"b61a08ab047654bb3856491fd348c11d4fcae01f"},{"introduced":"76e95978fa06e81ffc8abd947f83109a5958eb5f"},{"fixed":"f56123c30abf66dca7170c1546aa3a498484aab3"},{"introduced":"5555b0417c749a72fa485301068fb149fae09cfb"},{"fixed":"03addfbfd6e4fa02d19fcf51f74977c4107f85c9"},{"fixed":"e43643abfe51f54bd9208dd02298b366e9b9a847"}],"database_specific":{"cpe":"cpe:2.3:a:sparksolutions:spree:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"3.7.11"},{"introduced":"4.0.0"},{"fixed":"4.0.4"},{"introduced":"4.1.0"},{"fixed":"4.1.11"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["v3.7.10","v4.0.3","v4.1.10","v4.1.9","v4.1.8","v4.1.7","v4.1.6","v4.1.5","v4.1.4","v4.1.3","v4.1.2","v4.1.1","v4.1.0","v4.0.2","v3.7.9","v3.7.8","v4.0.1","v4.0.0","v3.7.6","v3.7.5","v3.7.4","v3.7.3","v3.7.2","v3.7.1","v3.7.0","v3.7.0.rc3","v3.7.0.rc2","v3.7.0.rc1","v3.7.0.beta","v3.6.0.rc1","v3.5.0.rc1","v3.4.0","v3.4.0.rc2","v3.4.0.rc1","v3.3.0","v3.3.0.rc4","v3.3.0.rc3","v3.2.2","v3.3.0.rc2","v3.3.0.rc1","v3.2.0.rc1","v3.1.0.rc1","v3.0.0.rc1","v2.4.0.rc2","v2.4.0.rc1","v1.2.0.rc1","v1.0.0.rc3","v1.0.0.rc2","v1.0.0.rc1","v0.70.0.rc2","v0.40.0","v0.11.99","v0.30.0.beta1","v0.11.0","v0.8.2","v0.4.0","v0.2.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-15269.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"}]}