{"id":"GHSA-m2jr-hmc3-qmpr","summary":"Authorization bypass in Spree","details":"### Impact\nThe perpetrator could query the [API v2 Order Status](https://guides.spreecommerce.org/api/v2/storefront#tag/Order-Status) endpoint with an empty string passed as an Order token\n\n### Patches\nPlease upgrade to 3.7.11, 4.0.4, or 4.1.11 depending on your used Spree version. Users of Spree \u003c 3.7 are not affected.\n\n### References\nPull request with a fix and in-depth explanation - https://github.com/spree/spree/pull/10573\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Email us at [security@spreecommerce.org](mailto:security@spreecommerce.org)","aliases":["CVE-2020-26223"],"modified":"2026-05-07T05:01:20.350008183Z","published":"2020-11-13T17:18:22Z","database_specific":{"cwe_ids":["CWE-863"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2020-11-13T17:18:00Z","nvd_published_at":null},"references":[{"type":"WEB","url":"https://github.com/spree/spree/security/advisories/GHSA-m2jr-hmc3-qmpr"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-26223"},{"type":"WEB","url":"https://github.com/spree/spree/pull/10573"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/spree_api/CVE-2020-26223.yml"},{"type":"PACKAGE","url":"https://github.com/spree/spree"},{"type":"WEB","url":"https://guides.spreecommerce.org/api/v2/storefront#tag/Order-Status"},{"type":"WEB","url":"https://rubygems.org/gems/spree_api/versions"}],"affected":[{"package":{"name":"spree_api","ecosystem":"RubyGems","purl":"pkg:gem/spree_api"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.7.0"},{"fixed":"3.7.13"}]}],"versions":["3.7.0","3.7.1","3.7.10","3.7.11","3.7.12","3.7.2","3.7.3","3.7.4","3.7.5","3.7.6","3.7.7","3.7.8","3.7.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/11/GHSA-m2jr-hmc3-qmpr/GHSA-m2jr-hmc3-qmpr.json"}},{"package":{"name":"spree_api","ecosystem":"RubyGems","purl":"pkg:gem/spree_api"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.0.0"},{"fixed":"4.0.5"}]}],"versions":["4.0.0","4.0.1","4.0.2","4.0.3","4.0.4"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/11/GHSA-m2jr-hmc3-qmpr/GHSA-m2jr-hmc3-qmpr.json"}},{"package":{"name":"spree_api","ecosystem":"RubyGems","purl":"pkg:gem/spree_api"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.1.0"},{"fixed":"4.1.12"}]}],"versions":["4.1.0","4.1.1","4.1.10","4.1.11","4.1.2","4.1.3","4.1.4","4.1.5","4.1.6","4.1.7","4.1.8","4.1.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/11/GHSA-m2jr-hmc3-qmpr/GHSA-m2jr-hmc3-qmpr.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"}]}