{"id":"GHSA-jxx8-v83v-rhw3","summary":"Spree Improper Input Validation vulnerability","details":"Spree Commerce 1.0.x before 2.0.0.rc1 allows remote authenticated administrators to instantiate arbitrary Ruby objects and execute arbitrary commands via the (1) `payment_method` parameter to `core/app/controllers/spree/admin/payment_methods_controller.rb`; and the (2) `promotion_action parameter` to `promotion_actions_controller.rb`, (3) `promotion_rule parameter` to `promotion_rules_controller.rb`, and (4) `calculator_type` parameter to `promotions_controller.rb` in `promo/app/controllers/spree/admin/`, related to unsafe use of the constantize function.","aliases":["CVE-2013-1656"],"modified":"2024-12-05T05:39:10.762524Z","published":"2017-10-24T18:33:37Z","database_specific":{"nvd_published_at":"2013-03-08T18:55:01Z","cwe_ids":["CWE-20"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2020-06-16T21:44:31Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2013-1656"},{"type":"WEB","url":"https://github.com/spree/spree/commit/70092eb55b8be8fe5d21a7658b62da658612fba7"},{"type":"WEB","url":"https://blog.convisoappsec.com/en/spree-commerce-multiple-unsafe-reflection-vulnerabilities-cve-2013-1656"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/spree/CVE-2013-1656.yml"},{"type":"PACKAGE","url":"https://github.com/spree/spree"},{"type":"WEB","url":"https://web.archive.org/web/20130907044454/https://www.conviso.com.br/advisories/CVE-2013-1656.txt"},{"type":"WEB","url":"https://web.archive.org/web/20140329142330/http://spreecommerce.com/blog/multiple-security-vulnerabilities-fixed"},{"type":"WEB","url":"https://web.archive.org/web/20140618100330/http://blog.conviso.com.br/2013/03/spree-commerce-multiple-unsafe.html"}],"affected":[{"package":{"name":"spree","ecosystem":"RubyGems","purl":"pkg:gem/spree"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.0.0"},{"fixed":"2.0.0.rc1"}]}],"versions":["1.0.0","1.0.1","1.0.2","1.0.3","1.0.4","1.0.6","1.0.7","1.1.0","1.1.0.rc1","1.1.0.rc2","1.1.1","1.1.2","1.1.2.rc1","1.1.3","1.1.4","1.1.5","1.1.6","1.2.0","1.2.0.rc1","1.2.0.rc2","1.2.2","1.2.3","1.2.4","1.2.5","1.3.0","1.3.0.rc1","1.3.0.rc2","1.3.1","1.3.2","1.3.3","1.3.4","1.3.5"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2017/10/GHSA-jxx8-v83v-rhw3/GHSA-jxx8-v83v-rhw3.json"}}],"schema_version":"1.9.0"}