This is a security release.
- Fix guest token fixation in
Spree::OrdersController, which allowed cart
takeover and disclosure of guest order details. See
GHSA-qj34-2493-vx9f.
All stores using solidus_frontend should upgrade.
This is a security release.
Spree::OrdersController, which allowed cartAll stores using solidus_frontend should upgrade.