MEDIUMRubyGems →
Ability to change order address without triggering address validations in solidus
Ability to change order address without triggering address validations in solidus
Affected packages
- solidus_api— before 2.8.6
- solidus_frontend— before 2.8.6
Exploit signal
- Known exploited (CISA KEV)
- No
- EPSS score
- —
- EPSS percentile
- —
EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.
Sources
- https://github.com/solidusio/solidus/security/advisories/GHSA-3mvg-rrrw-m7ph
- https://nvd.nist.gov/vuln/detail/CVE-2020-15109
- https://gist.github.com/kennyadsl/4618cd9797984cb64f7700a81bda889d
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/solidus_api/CVE-2020-15109.yml
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/solidus_frontend/CVE-2020-15109.yml
- https://github.com/solidusio/solidus
- https://solidus.io/blog/2020/07/16/new-releases.html
Structured record: https://osv.dev/vulnerability/GHSA-3mvg-rrrw-m7ph
Recommended response stack
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.
Get incidents like this as alerts for your stack.
Join the beta