Executive brief
spree_auth_devise allows remote authenticated users to assign themselves arbitrary roles
Affected products
- RubyGems spree_auth_devise
Junglewise Threat Intelligence
CVE-2013-2506 · Severity: info · Published 2022-05-17
Technologies: spree_auth_devise (RubyGems). Vendors: RubyGems.
spree_auth_devise allows remote authenticated users to assign themselves arbitrary roles