« Volver al listado

CVE-2013-1656

Estado: ModificadaMedia (4.3)—

Spree Commerce 1.0.x through 1.3.2 allows remote authenticated administrators to instantiate arbitrary Ruby objects and execute arbitrary commands via the (1) payment_method parameter to core/app/controllers/spree/admin/payment_methods_controller.rb; and the (2) promotion_action parameter to promotion_actions_controller.rb, (3) promotion_rule parameter to promotion_rules_controller.rb, and (4) calculator_type parameter to promotions_controller.rb in promo/app/controllers/spree/admin/, related to unsafe use of the constantize function.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2013-1656",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2013-03-08T18:55:01.637",
  "references": [
    {
      "url": "http://blog.conviso.com.br/2013/03/spree-commerce-multiple-unsafe.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://spreecommerce.com/blog/multiple-security-vulnerabilities-fixed",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://www.conviso.com.br/advisories/CVE-2013-1656.txt",
      "tags": [
        "Exploit"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://blog.conviso.com.br/2013/03/spree-commerce-multiple-unsafe.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://spreecommerce.com/blog/multiple-security-vulnerabilities-fixed",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.conviso.com.br/advisories/CVE-2013-1656.txt",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Spree Commerce 1.0.x through 1.3.2 allows remote authenticated administrators to instantiate arbitrary Ruby objects and execute arbitrary commands via the (1) payment_method parameter to core/app/controllers/spree/admin/payment_methods_controller.rb; and the (2) promotion_action parameter to promotion_actions_controller.rb, (3) promotion_rule parameter to promotion_rules_controller.rb, and (4) calculator_type parameter to promotions_controller.rb in promo/app/controllers/spree/admin/, related to unsafe use of the constantize function."
    },
    {
      "lang": "es",
      "value": "Spree Commerce 1.0.x hasta la versión 1.3.2 permite a administradores autenticados remotos instanciar objetos Ruby arbitrarios y ejecutar comandos arbitrarios a través de el parámetro (1) payment_method en core/app/controllers/spree/admin/payment_methods_controller.rb; y (2) promotion_action en promotion_actions_controller.rb, (3) promotion_rule en promotion_rules_controller.rb y (4) calculator_type en promotions_controller.rb en promo/app/controllers/spree/admin/, relacionado con la utilización insegura de la función constantize."
    }
  ],
  "lastModified": "2026-06-16T23:51:51.280",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:spreecommerce:spree:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AC68F68B-6670-46DB-ABE2-03235CF421AD",
              "versionEndIncluding": "1.3.2"
            },
            {
              "criteria": "cpe:2.3:a:spreecommerce:spree:1.0.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "21148132-CBE3-4556-90F2-A1AEB6E90441"
            },
            {
              "criteria": "cpe:2.3:a:spreecommerce:spree:1.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "06D5D1B2-21FD-439E-9401-FE8CDB5D8289"
            },
            {
              "criteria": "cpe:2.3:a:spreecommerce:spree:1.0.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B12C638A-6087-4300-A2E4-88A746894646"
            },
            {
              "criteria": "cpe:2.3:a:spreecommerce:spree:1.0.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1EEFE273-624C-4F83-8B00-C35BF3C07AA6"
            },
            {
              "criteria": "cpe:2.3:a:spreecommerce:spree:1.0.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "63C90684-F41D-4C94-9C7C-CC26C6C12E5D"
            },
            {
              "criteria": "cpe:2.3:a:spreecommerce:spree:1.0.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "152A3126-C776-4D9C-AB48-48E65380A475"
            },
            {
              "criteria": "cpe:2.3:a:spreecommerce:spree:1.0.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B2C4A43D-B5C8-42F4-9D21-979F9F60A272"
            },
            {
              "criteria": "cpe:2.3:a:spreecommerce:spree:1.0.7:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D1B62694-25F2-4324-8A90-B53D8D9815B0"
            },
            {
              "criteria": "cpe:2.3:a:spreecommerce:spree:1.1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3E4C456B-99E3-4550-9F03-74E828EADC49"
            },
            {
              "criteria": "cpe:2.3:a:spreecommerce:spree:1.1.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C8AE2CB0-58FE-485F-8722-0F6799FEE97B"
            },
            {
              "criteria": "cpe:2.3:a:spreecommerce:spree:1.1.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7B1C92A9-CDC0-422F-868A-1DEF9887BC27"
            },
            {
              "criteria": "cpe:2.3:a:spreecommerce:spree:1.1.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F8A05B3F-8F92-421E-A18B-FEEB9EF672A9"
            },
            {
              "criteria": "cpe:2.3:a:spreecommerce:spree:1.1.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9B58ACE5-EA8E-4266-BC0C-86B34439BA1C"
            },
            {
              "criteria": "cpe:2.3:a:spreecommerce:spree:1.1.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C3258380-E9CA-4F59-92BD-E568B7FE823F"
            },
            {
              "criteria": "cpe:2.3:a:spreecommerce:spree:1.1.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E5A0F16F-EEA6-496A-83CC-EE87DF06195F"
            },
            {
              "criteria": "cpe:2.3:a:spreecommerce:spree:1.2.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E4A78A39-0D61-4935-927A-EAFC904D1BD3"
            },
            {
              "criteria": "cpe:2.3:a:spreecommerce:spree:1.2.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E7E9A11C-BDAC-4F21-B165-9CB6636FD45B"
            },
            {
              "criteria": "cpe:2.3:a:spreecommerce:spree:1.2.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8CD9FB6C-D1C5-4D96-88B6-C24C36EF4679"
            },
            {
              "criteria": "cpe:2.3:a:spreecommerce:spree:1.2.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3B3C7D8B-3BF3-47FE-9197-5171A07ED7D2"
            },
            {
              "criteria": "cpe:2.3:a:spreecommerce:spree:1.2.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3015DFDE-8BAB-4A85-BAC4-370FDE089C0E"
            },
            {
              "criteria": "cpe:2.3:a:spreecommerce:spree:1.3.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F31E7395-CCA8-4ABE-8461-83F152D52443"
            },
            {
              "criteria": "cpe:2.3:a:spreecommerce:spree:1.3.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "75DA34B2-C070-4457-9623-371E8DF8B648"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}