Skip to content

Commit bdc21f9

Browse files
jasnowRubySec CI
authored andcommitted
Updated advisory posts against rubysec/ruby-advisory-db@fb34fed
1 parent f9763d3 commit bdc21f9

3 files changed

Lines changed: 129 additions & 5 deletions

File tree

‎advisories/_posts/2026-06-22-CVE-2026-61570.md‎

Lines changed: 7 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,7 @@ advisory:
88
gem: mpxj
99
cve: 2026-61570
1010
ghsa: 5vvx-3h34-f3gj
11-
url: https://www.cve.org/CVERecord/SearchResults?query=CVE-2026-61570
11+
url: https://nvd.nist.gov/vuln/detail/CVE-2026-61570
1212
title: XXE Vulnerability in MerlinReader
1313
date: 2026-06-22
1414
description: |-
@@ -36,12 +36,14 @@ advisory:
3636
- ">= 16.4.1"
3737
related:
3838
url:
39-
- https://www.cve.org/CVERecord/SearchResults?query=CVE-2026-61570
39+
- https://nvd.nist.gov/vuln/detail/CVE-2026-61570
4040
- https://rubygems.org/gems/mpxj/versions/16.4.1
4141
- https://github.com/joniles/mpxj/releases/tag/v16.4.1
42+
- https://github.com/joniles/mpxj/blob/master/CHANGELOG.md#1641-2026-06-22
43+
- https://osv.dev/vulnerability/GHSA-5vvx-3h34-f3gj
4244
- https://github.com/joniles/mpxj/security/advisories/GHSA-5vvx-3h34-f3gj
45+
- https://github.com/advisories/GHSA-5vvx-3h34-f3gj
4346
notes: |
44-
- CVE is reserved, but not published.
45-
- cvss_v3 value from GHSA.
46-
- data from gem release date.
47+
- cvss_v3 from GHSA and nvd.nist.gov URLs.
48+
- date from gem release date.
4749
---
Lines changed: 42 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,42 @@
1+
---
2+
layout: advisory
3+
title: 'CVE-2026-65829 (mpxj): Potential Path Traversal Vulnerability in Primavera
4+
P3 PRX and SureTrak STX readers'
5+
comments: false
6+
categories:
7+
- mpxj
8+
advisory:
9+
gem: mpxj
10+
cve: 2026-65829
11+
ghsa: 7952-gx68-cjqr
12+
url: https://nvd.nist.gov/vuln/detail/CVE-2026-65829
13+
title: Potential Path Traversal Vulnerability in Primavera P3 PRX and SureTrak STX
14+
readers
15+
date: 2026-07-03
16+
description: |-
17+
## Impact
18+
19+
When reading a suitably crafted PRX or STX file, MPXJ can be made
20+
to write files to arbitrary locations in the file system.
21+
22+
## Workarounds
23+
24+
Do not read PRX or STX files from untrusted sources.
25+
cvss_v3: 5.3
26+
unaffected_versions:
27+
- "< 7.3.0"
28+
patched_versions:
29+
- ">= 16.5.0"
30+
related:
31+
url:
32+
- https://nvd.nist.gov/vuln/detail/CVE-2026-65829
33+
- https://rubygems.org/gems/mpxj/versions/16.5.0
34+
- https://github.com/joniles/mpxj/releases/tag/v16.5.0
35+
- https://github.com/joniles/mpxj/blob/master/CHANGELOG.md#1650-2026-07-03
36+
- https://github.com/joniles/mpxj/commit/4347315afab1ef5a2907978a754fbc5b0ff58e6f
37+
- https://github.com/joniles/mpxj/security/advisories/GHSA-7952-gx68-cjqr
38+
- https://github.com/advisories/GHSA-7952-gx68-cjqr
39+
notes: |
40+
- cvss_v3 from GHSA and nvd.nist.gov URLs.
41+
- date from rubygems.org URL.
42+
---
Lines changed: 80 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,80 @@
1+
---
2+
layout: advisory
3+
title: 'CVE-2026-94462 (spree_api): Broken Access Control in `PATCH /api/v3/store/carts/:id/associate`
4+
(IDOR)'
5+
comments: false
6+
categories:
7+
- spree_api
8+
advisory:
9+
gem: spree_api
10+
cve: 2026-94462
11+
ghsa: 4825-p4xm-pcf2
12+
url: https://nvd.nist.gov/vuln/detail/CVE-2026-94462
13+
title: Broken Access Control in `PATCH /api/v3/store/carts/:id/associate` (IDOR)
14+
date: 2026-07-20
15+
description: |-
16+
## Summary
17+
18+
The Store API v3 endpoint PATCH /api/v3/store/carts/:id/associate binds
19+
a guest cart to the authenticated caller without verifying possession
20+
of that cart. It locates the cart by prefixed ID only —
21+
current_store.carts.where(user: [nil, current_user]).find_by_prefix_id!(
22+
params[:id]) — and omits the authorize!(:update, @cart, cart_token)
23+
check that every other action in the controller performs via CartResolvable.
24+
Because prefixed IDs are a reversible Sqids encoding of the auto-increment
25+
primary key (obfuscation, not a token), an authenticated customer can
26+
name arbitrary guest cart IDs, take them over, and read the checkout
27+
addresses stored on them. This is broken access control / IDOR,
28+
reachable by any low-privilege registered user.
29+
30+
## Severity
31+
32+
Requires an authenticated store account and depends on target guest
33+
carts already carrying an address and not yet being associated, on a
34+
store not running in login_required mode. Confidentiality impact is
35+
the driver (guest checkout PII); integrity impact is limited and
36+
recoverable (cart reassignment + email overwrite on an in-progress
37+
cart). Not Critical: the action is gated behind authentication (PR:L, not
38+
PR:N) and constrained by cart state, so it is not anonymously exploitable.
39+
40+
## Impact
41+
42+
Confidentiality: an authenticated attacker can enumerate guest cart
43+
IDs and read checkout PII (name, street, postal code, phone) on carts
44+
they don't own. Integrity: limited and recoverable — each call reassigns
45+
the guest cart and overwrites its email, disrupting the original
46+
guest's in-progress cart. Requires a registered account, so not
47+
anonymously exploitable.
48+
49+
## Remediation
50+
51+
Update to Spree 5.4.4 or 5.5.4.
52+
53+
Your storefront, based on https://github.com/spree/storefront,
54+
doesn't need any updates because it has always sent a cart
55+
token when associating carts; this is a backend issue.
56+
cvss_v3: 7.1
57+
unaffected_versions:
58+
- "< 5.4.0"
59+
patched_versions:
60+
- "~> 5.4.4"
61+
- ">= 5.5.4"
62+
related:
63+
url:
64+
- https://nvd.nist.gov/vuln/detail/CVE-2026-94462
65+
- https://rubygems.org/gems/spree_api/versions/5.5.4
66+
- https://github.com/spree/spree/releases/tag/v5.5.4
67+
- https://github.com/spree/spree/commit/af0d1a2d582a60d179de65b7d3ea024cb26426a8
68+
- https://rubygems.org/gems/spree_api/versions/5.4.4
69+
- https://github.com/spree/spree/releases/tag/v5.4.4
70+
- https://github.com/spree/spree/commit/8834230a1f47bb5988f23f45dbd162776cf592bd
71+
- https://github.com/spree/spree/pull/14314
72+
- https://advisories.gitlab.com/gem/spree_api/CVE-2026-94462
73+
- https://osv.dev/vulnerability/GHSA-4825-p4xm-pcf2
74+
- https://github.com/spree/spree/security/advisories/GHSA-4825-p4xm-pcf2
75+
- https://github.com/advisories/GHSA-4825-p4xm-pcf2
76+
notes: |
77+
- NOTE: Gem name is "spree_api" but repo name is "spree".
78+
- cvss_v3 from GHSA and nvd.nist.gov URLs.
79+
- date field is rubygems.org release date.
80+
---

0 commit comments

Comments
 (0)