Vulnerabilities (CVE)

Filtered by vendor Spreecommerce
Filtered by product Spree Auth Devise
Angry Yack Logo
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-41275 1 Spreecommerce 1 Spree Auth Devise 2024-11-21 6.8 MEDIUM 9.3 CRITICAL
spree_auth_devise is an open source library which provides authentication and authorization services for use with the Spree storefront framework by using an underlying Devise authentication framework. In affected versions spree_auth_devise is subject to a CSRF vulnerability that allows user account takeover. All applications using any version of the frontend component of spree_auth_devise are affected if protect_from_forgery method is both: Executed whether as: A before_action callback (the defa ...

Show More