A security vulnerability (CVE-2026-22588) in Spree API allows authenticated users to access other users' address information through an Insecure Direct Object Reference (IDOR) flaw. By manipulating address identifiers when updating their own orders via the /api/v2/storefront/checkout endpoint, attackers can retrieve and

1m read timeFrom rubysec.com
Post cover image
Table of contents
ADVISORIESGEMSEVERITYUNAFFECTED VERSIONSPATCHED VERSIONSDESCRIPTIONSummaryDetailsImpactRELATED

Sort: