github spree/spree v4.0.3
Version 4.0.3

latest releases: v4.8.1, v4.8.0, v4.7.3...
4 years ago

This security release is recommended for all Spree 4.0 installations

Fixes security issue with API v2 Order information 72e1d44

An attacker could expose Order information using brute force to guess Order numbers. This patch fixes it by requiring Order token to obtain Order information from API v2 Order Status endpoint.

Don't miss a new spree release

NewReleases is sending notifications on new releases.