Skip to content

v4.6.3

Latest

Choose a tag to compare

@jarednorman jarednorman released this 09 Sep 13:42
· 5 commits to main since this release

This is a security release.

  • Fix guest token fixation in Spree::OrdersController, which allowed cart
    takeover and disclosure of guest order details. See
    GHSA-qj34-2493-vx9f.

All stores using solidus_frontend should upgrade.