Improper Authorization in spree_api - CVE-2020-15269

 

Improper Authorization in spree_api - CVE-2020-15269

Published: October 20, 2020 / Updated: April 27, 2026


Vulnerability identifier: #VU128100
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-15269
CWE-ID: CWE-285
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to gain unauthorized access to Storefront API v2 endpoints.

The vulnerability exists due to improper access control in API v2 authentication when handling requests with an expired doorkeeper token. A remote user can present a previously obtained expired user token to gain unauthorized access to Storefront API v2 endpoints.

The issue affects authentication of requests to Storefront API v2 endpoints using old expired user tokens.


Affected software

spree_api

How to mitigate CVE-2020-15269

Install security update from vendor's website.

spree_api - addressed in versions 3.7.11, 4.0.4, 4.1.11

External References

Related Security Bulletins