Vulnerabilities (CVE)

Filtered by vendor Nebulab
Filtered by product Solidus Auth Devise
Angry Yack Logo
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-41274 1 Nebulab 1 Solidus Auth Devise 2024-11-21 6.8 MEDIUM 9.3 CRITICAL
solidus_auth_devise provides authentication services for the Solidus webstore framework, using the Devise gem. In affected versions solidus_auth_devise is subject to a CSRF vulnerability that allows user account takeover. All applications using any version of the frontend component of `solidus_auth_devise` are affected if `protect_from_forgery` method is both: Executed whether as: A `before_action` callback (the default) or A `prepend_before_action` (option `prepend: true` given) before the `:lo ...

Show More