solidus_auth_devise
Provides authentication and authorization services for use with Solidus by using Devise and CanCan.
Activity
- Latest release
- 5mo ago
- Total releases
- 30
- Cadence
- ~2 months
- Last 12 months
- 1
Reach
- Stars
- —
Details
- License
- BSD-3-Clause
- First release
- May 26, 2015
| Version | Released | |
|---|---|---|
2.6.0
minor
|
2.6.0
minor
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
2.5.9
patch
|
2.5.9
patch
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
2.5.8
patch
|
2.5.8
patch
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
2.5.7
patch
|
2.5.7
patch
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
2.5.6
patch
|
2.5.6
patch
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
2.5.5
patch
|
2.5.5
patch
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
2.5.4
patch
|
2.5.4
patch
Dependencies (8)
Changelog
Compare changes
|
|
2.5.3
patch
1 CVE
CVE-2021-41274
GHSA-xm34-v85h-9pg2
Nov 18, 2021
Authentication Bypass by CSRF Weakness
9.3
/ 10
Critical
Network
Low
None
Required
Changed
High
High
None
ImpactCSRF vulnerability that allows user account takeover. All applications using any version of the frontend component of
That means that applications that haven't been configured differently from what it's generated with Rails aren't affected. PatchesUsers should promptly update to WorkaroundsA couple of options:
ReferencesThanksWe'd like to thank vampire000 for reporting this issue. For more informationIf you have any questions or comments about this advisory:
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.4.0
1.5.0
1.6.0
1.6.1
1.6.2
+ 11 more Show less
1.6.3
1.6.4
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
Fixed in
2.5.4
References
Updated Jul 08, 2026 · Source: OSV.dev |
2.5.3
patch
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
2.5.2
patch
1 CVE
CVE-2021-41274
GHSA-xm34-v85h-9pg2
Nov 18, 2021
Authentication Bypass by CSRF Weakness
9.3
/ 10
Critical
Network
Low
None
Required
Changed
High
High
None
ImpactCSRF vulnerability that allows user account takeover. All applications using any version of the frontend component of
That means that applications that haven't been configured differently from what it's generated with Rails aren't affected. PatchesUsers should promptly update to WorkaroundsA couple of options:
ReferencesThanksWe'd like to thank vampire000 for reporting this issue. For more informationIf you have any questions or comments about this advisory:
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.4.0
1.5.0
1.6.0
1.6.1
1.6.2
+ 11 more Show less
1.6.3
1.6.4
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
Fixed in
2.5.4
References
Updated Jul 08, 2026 · Source: OSV.dev |
2.5.2
patch
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
2.5.1
patch
1 CVE
CVE-2021-41274
GHSA-xm34-v85h-9pg2
Nov 18, 2021
Authentication Bypass by CSRF Weakness
9.3
/ 10
Critical
Network
Low
None
Required
Changed
High
High
None
ImpactCSRF vulnerability that allows user account takeover. All applications using any version of the frontend component of
That means that applications that haven't been configured differently from what it's generated with Rails aren't affected. PatchesUsers should promptly update to WorkaroundsA couple of options:
ReferencesThanksWe'd like to thank vampire000 for reporting this issue. For more informationIf you have any questions or comments about this advisory:
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.4.0
1.5.0
1.6.0
1.6.1
1.6.2
+ 11 more Show less
1.6.3
1.6.4
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
Fixed in
2.5.4
References
Updated Jul 08, 2026 · Source: OSV.dev |
2.5.1
patch
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
2.5.0
minor
1 CVE
CVE-2021-41274
GHSA-xm34-v85h-9pg2
Nov 18, 2021
Authentication Bypass by CSRF Weakness
9.3
/ 10
Critical
Network
Low
None
Required
Changed
High
High
None
ImpactCSRF vulnerability that allows user account takeover. All applications using any version of the frontend component of
That means that applications that haven't been configured differently from what it's generated with Rails aren't affected. PatchesUsers should promptly update to WorkaroundsA couple of options:
ReferencesThanksWe'd like to thank vampire000 for reporting this issue. For more informationIf you have any questions or comments about this advisory:
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.4.0
1.5.0
1.6.0
1.6.1
1.6.2
+ 11 more Show less
1.6.3
1.6.4
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
Fixed in
2.5.4
References
Updated Jul 08, 2026 · Source: OSV.dev |
2.5.0
minor
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
2.4.0
minor
1 CVE
CVE-2021-41274
GHSA-xm34-v85h-9pg2
Nov 18, 2021
Authentication Bypass by CSRF Weakness
9.3
/ 10
Critical
Network
Low
None
Required
Changed
High
High
None
ImpactCSRF vulnerability that allows user account takeover. All applications using any version of the frontend component of
That means that applications that haven't been configured differently from what it's generated with Rails aren't affected. PatchesUsers should promptly update to WorkaroundsA couple of options:
ReferencesThanksWe'd like to thank vampire000 for reporting this issue. For more informationIf you have any questions or comments about this advisory:
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.4.0
1.5.0
1.6.0
1.6.1
1.6.2
+ 11 more Show less
1.6.3
1.6.4
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
Fixed in
2.5.4
References
Updated Jul 08, 2026 · Source: OSV.dev |
2.4.0
minor
Dependencies (23)
+ 15 more
Changelog
Compare changes
|
|
2.3.0
minor
1 CVE
CVE-2021-41274
GHSA-xm34-v85h-9pg2
Nov 18, 2021
Authentication Bypass by CSRF Weakness
9.3
/ 10
Critical
Network
Low
None
Required
Changed
High
High
None
ImpactCSRF vulnerability that allows user account takeover. All applications using any version of the frontend component of
That means that applications that haven't been configured differently from what it's generated with Rails aren't affected. PatchesUsers should promptly update to WorkaroundsA couple of options:
ReferencesThanksWe'd like to thank vampire000 for reporting this issue. For more informationIf you have any questions or comments about this advisory:
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.4.0
1.5.0
1.6.0
1.6.1
1.6.2
+ 11 more Show less
1.6.3
1.6.4
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
Fixed in
2.5.4
References
Updated Jul 08, 2026 · Source: OSV.dev |
2.3.0
minor
Dependencies (22)
+ 14 more
Changelog
Compare changes
|
|
2.2.0
minor
1 CVE
CVE-2021-41274
GHSA-xm34-v85h-9pg2
Nov 18, 2021
Authentication Bypass by CSRF Weakness
9.3
/ 10
Critical
Network
Low
None
Required
Changed
High
High
None
ImpactCSRF vulnerability that allows user account takeover. All applications using any version of the frontend component of
That means that applications that haven't been configured differently from what it's generated with Rails aren't affected. PatchesUsers should promptly update to WorkaroundsA couple of options:
ReferencesThanksWe'd like to thank vampire000 for reporting this issue. For more informationIf you have any questions or comments about this advisory:
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.4.0
1.5.0
1.6.0
1.6.1
1.6.2
+ 11 more Show less
1.6.3
1.6.4
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
Fixed in
2.5.4
References
Updated Jul 08, 2026 · Source: OSV.dev |
2.2.0
minor
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
2.1.0
minor
1 CVE
CVE-2021-41274
GHSA-xm34-v85h-9pg2
Nov 18, 2021
Authentication Bypass by CSRF Weakness
9.3
/ 10
Critical
Network
Low
None
Required
Changed
High
High
None
ImpactCSRF vulnerability that allows user account takeover. All applications using any version of the frontend component of
That means that applications that haven't been configured differently from what it's generated with Rails aren't affected. PatchesUsers should promptly update to WorkaroundsA couple of options:
ReferencesThanksWe'd like to thank vampire000 for reporting this issue. For more informationIf you have any questions or comments about this advisory:
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.4.0
1.5.0
1.6.0
1.6.1
1.6.2
+ 11 more Show less
1.6.3
1.6.4
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
Fixed in
2.5.4
References
Updated Jul 08, 2026 · Source: OSV.dev |
2.1.0
minor
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
2.0.0
major
1 CVE
CVE-2021-41274
GHSA-xm34-v85h-9pg2
Nov 18, 2021
Authentication Bypass by CSRF Weakness
9.3
/ 10
Critical
Network
Low
None
Required
Changed
High
High
None
ImpactCSRF vulnerability that allows user account takeover. All applications using any version of the frontend component of
That means that applications that haven't been configured differently from what it's generated with Rails aren't affected. PatchesUsers should promptly update to WorkaroundsA couple of options:
ReferencesThanksWe'd like to thank vampire000 for reporting this issue. For more informationIf you have any questions or comments about this advisory:
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.4.0
1.5.0
1.6.0
1.6.1
1.6.2
+ 11 more Show less
1.6.3
1.6.4
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
Fixed in
2.5.4
References
Updated Jul 08, 2026 · Source: OSV.dev |
2.0.0
major
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
1.6.4
patch
1 CVE
CVE-2021-41274
GHSA-xm34-v85h-9pg2
Nov 18, 2021
Authentication Bypass by CSRF Weakness
9.3
/ 10
Critical
Network
Low
None
Required
Changed
High
High
None
ImpactCSRF vulnerability that allows user account takeover. All applications using any version of the frontend component of
That means that applications that haven't been configured differently from what it's generated with Rails aren't affected. PatchesUsers should promptly update to WorkaroundsA couple of options:
ReferencesThanksWe'd like to thank vampire000 for reporting this issue. For more informationIf you have any questions or comments about this advisory:
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.4.0
1.5.0
1.6.0
1.6.1
1.6.2
+ 11 more Show less
1.6.3
1.6.4
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
Fixed in
2.5.4
References
Updated Jul 08, 2026 · Source: OSV.dev |
1.6.4
patch
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
1.6.3
patch
1 CVE
CVE-2021-41274
GHSA-xm34-v85h-9pg2
Nov 18, 2021
Authentication Bypass by CSRF Weakness
9.3
/ 10
Critical
Network
Low
None
Required
Changed
High
High
None
ImpactCSRF vulnerability that allows user account takeover. All applications using any version of the frontend component of
That means that applications that haven't been configured differently from what it's generated with Rails aren't affected. PatchesUsers should promptly update to WorkaroundsA couple of options:
ReferencesThanksWe'd like to thank vampire000 for reporting this issue. For more informationIf you have any questions or comments about this advisory:
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.4.0
1.5.0
1.6.0
1.6.1
1.6.2
+ 11 more Show less
1.6.3
1.6.4
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
Fixed in
2.5.4
References
Updated Jul 08, 2026 · Source: OSV.dev |
1.6.3
patch
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
1.6.2
patch
1 CVE
CVE-2021-41274
GHSA-xm34-v85h-9pg2
Nov 18, 2021
Authentication Bypass by CSRF Weakness
9.3
/ 10
Critical
Network
Low
None
Required
Changed
High
High
None
ImpactCSRF vulnerability that allows user account takeover. All applications using any version of the frontend component of
That means that applications that haven't been configured differently from what it's generated with Rails aren't affected. PatchesUsers should promptly update to WorkaroundsA couple of options:
ReferencesThanksWe'd like to thank vampire000 for reporting this issue. For more informationIf you have any questions or comments about this advisory:
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.4.0
1.5.0
1.6.0
1.6.1
1.6.2
+ 11 more Show less
1.6.3
1.6.4
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
Fixed in
2.5.4
References
Updated Jul 08, 2026 · Source: OSV.dev |
1.6.2
patch
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
1.6.1
patch
1 CVE
CVE-2021-41274
GHSA-xm34-v85h-9pg2
Nov 18, 2021
Authentication Bypass by CSRF Weakness
9.3
/ 10
Critical
Network
Low
None
Required
Changed
High
High
None
ImpactCSRF vulnerability that allows user account takeover. All applications using any version of the frontend component of
That means that applications that haven't been configured differently from what it's generated with Rails aren't affected. PatchesUsers should promptly update to WorkaroundsA couple of options:
ReferencesThanksWe'd like to thank vampire000 for reporting this issue. For more informationIf you have any questions or comments about this advisory:
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.4.0
1.5.0
1.6.0
1.6.1
1.6.2
+ 11 more Show less
1.6.3
1.6.4
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
Fixed in
2.5.4
References
Updated Jul 08, 2026 · Source: OSV.dev |
1.6.1
patch
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
1.6.0
minor
1 CVE
CVE-2021-41274
GHSA-xm34-v85h-9pg2
Nov 18, 2021
Authentication Bypass by CSRF Weakness
9.3
/ 10
Critical
Network
Low
None
Required
Changed
High
High
None
ImpactCSRF vulnerability that allows user account takeover. All applications using any version of the frontend component of
That means that applications that haven't been configured differently from what it's generated with Rails aren't affected. PatchesUsers should promptly update to WorkaroundsA couple of options:
ReferencesThanksWe'd like to thank vampire000 for reporting this issue. For more informationIf you have any questions or comments about this advisory:
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.4.0
1.5.0
1.6.0
1.6.1
1.6.2
+ 11 more Show less
1.6.3
1.6.4
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
Fixed in
2.5.4
References
Updated Jul 08, 2026 · Source: OSV.dev |
1.6.0
minor
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
1.5.0
minor
1 CVE
CVE-2021-41274
GHSA-xm34-v85h-9pg2
Nov 18, 2021
Authentication Bypass by CSRF Weakness
9.3
/ 10
Critical
Network
Low
None
Required
Changed
High
High
None
ImpactCSRF vulnerability that allows user account takeover. All applications using any version of the frontend component of
That means that applications that haven't been configured differently from what it's generated with Rails aren't affected. PatchesUsers should promptly update to WorkaroundsA couple of options:
ReferencesThanksWe'd like to thank vampire000 for reporting this issue. For more informationIf you have any questions or comments about this advisory:
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.4.0
1.5.0
1.6.0
1.6.1
1.6.2
+ 11 more Show less
1.6.3
1.6.4
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
Fixed in
2.5.4
References
Updated Jul 08, 2026 · Source: OSV.dev |
1.5.0
minor
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
1.4.0
minor
1 CVE
CVE-2021-41274
GHSA-xm34-v85h-9pg2
Nov 18, 2021
Authentication Bypass by CSRF Weakness
9.3
/ 10
Critical
Network
Low
None
Required
Changed
High
High
None
ImpactCSRF vulnerability that allows user account takeover. All applications using any version of the frontend component of
That means that applications that haven't been configured differently from what it's generated with Rails aren't affected. PatchesUsers should promptly update to WorkaroundsA couple of options:
ReferencesThanksWe'd like to thank vampire000 for reporting this issue. For more informationIf you have any questions or comments about this advisory:
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.4.0
1.5.0
1.6.0
1.6.1
1.6.2
+ 11 more Show less
1.6.3
1.6.4
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
Fixed in
2.5.4
References
Updated Jul 08, 2026 · Source: OSV.dev |
1.4.0
minor
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
1.3.0
minor
1 CVE
CVE-2021-41274
GHSA-xm34-v85h-9pg2
Nov 18, 2021
Authentication Bypass by CSRF Weakness
9.3
/ 10
Critical
Network
Low
None
Required
Changed
High
High
None
ImpactCSRF vulnerability that allows user account takeover. All applications using any version of the frontend component of
That means that applications that haven't been configured differently from what it's generated with Rails aren't affected. PatchesUsers should promptly update to WorkaroundsA couple of options:
ReferencesThanksWe'd like to thank vampire000 for reporting this issue. For more informationIf you have any questions or comments about this advisory:
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.4.0
1.5.0
1.6.0
1.6.1
1.6.2
+ 11 more Show less
1.6.3
1.6.4
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
Fixed in
2.5.4
References
Updated Jul 08, 2026 · Source: OSV.dev |
1.3.0
minor
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
1.2.3
patch
1 CVE
CVE-2021-41274
GHSA-xm34-v85h-9pg2
Nov 18, 2021
Authentication Bypass by CSRF Weakness
9.3
/ 10
Critical
Network
Low
None
Required
Changed
High
High
None
ImpactCSRF vulnerability that allows user account takeover. All applications using any version of the frontend component of
That means that applications that haven't been configured differently from what it's generated with Rails aren't affected. PatchesUsers should promptly update to WorkaroundsA couple of options:
ReferencesThanksWe'd like to thank vampire000 for reporting this issue. For more informationIf you have any questions or comments about this advisory:
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.4.0
1.5.0
1.6.0
1.6.1
1.6.2
+ 11 more Show less
1.6.3
1.6.4
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
Fixed in
2.5.4
References
Updated Jul 08, 2026 · Source: OSV.dev |
1.2.3
patch
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
1.2.2
patch
1 CVE
CVE-2021-41274
GHSA-xm34-v85h-9pg2
Nov 18, 2021
Authentication Bypass by CSRF Weakness
9.3
/ 10
Critical
Network
Low
None
Required
Changed
High
High
None
ImpactCSRF vulnerability that allows user account takeover. All applications using any version of the frontend component of
That means that applications that haven't been configured differently from what it's generated with Rails aren't affected. PatchesUsers should promptly update to WorkaroundsA couple of options:
ReferencesThanksWe'd like to thank vampire000 for reporting this issue. For more informationIf you have any questions or comments about this advisory:
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.4.0
1.5.0
1.6.0
1.6.1
1.6.2
+ 11 more Show less
1.6.3
1.6.4
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
Fixed in
2.5.4
References
Updated Jul 08, 2026 · Source: OSV.dev |
1.2.2
patch
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
1.2.1
patch
1 CVE
CVE-2021-41274
GHSA-xm34-v85h-9pg2
Nov 18, 2021
Authentication Bypass by CSRF Weakness
9.3
/ 10
Critical
Network
Low
None
Required
Changed
High
High
None
ImpactCSRF vulnerability that allows user account takeover. All applications using any version of the frontend component of
That means that applications that haven't been configured differently from what it's generated with Rails aren't affected. PatchesUsers should promptly update to WorkaroundsA couple of options:
ReferencesThanksWe'd like to thank vampire000 for reporting this issue. For more informationIf you have any questions or comments about this advisory:
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.4.0
1.5.0
1.6.0
1.6.1
1.6.2
+ 11 more Show less
1.6.3
1.6.4
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
Fixed in
2.5.4
References
Updated Jul 08, 2026 · Source: OSV.dev |
1.2.1
patch
Dependencies (17)
+ 9 more
Changelog
Compare changes
|
|
1.2.0
minor
1 CVE
CVE-2021-41274
GHSA-xm34-v85h-9pg2
Nov 18, 2021
Authentication Bypass by CSRF Weakness
9.3
/ 10
Critical
Network
Low
None
Required
Changed
High
High
None
ImpactCSRF vulnerability that allows user account takeover. All applications using any version of the frontend component of
That means that applications that haven't been configured differently from what it's generated with Rails aren't affected. PatchesUsers should promptly update to WorkaroundsA couple of options:
ReferencesThanksWe'd like to thank vampire000 for reporting this issue. For more informationIf you have any questions or comments about this advisory:
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.4.0
1.5.0
1.6.0
1.6.1
1.6.2
+ 11 more Show less
1.6.3
1.6.4
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
Fixed in
2.5.4
References
Updated Jul 08, 2026 · Source: OSV.dev |
1.2.0
minor
Dependencies (17)
+ 9 more
Changelog
Compare changes
|
|
1.1.0
minor
1 CVE
CVE-2021-41274
GHSA-xm34-v85h-9pg2
Nov 18, 2021
Authentication Bypass by CSRF Weakness
9.3
/ 10
Critical
Network
Low
None
Required
Changed
High
High
None
ImpactCSRF vulnerability that allows user account takeover. All applications using any version of the frontend component of
That means that applications that haven't been configured differently from what it's generated with Rails aren't affected. PatchesUsers should promptly update to WorkaroundsA couple of options:
ReferencesThanksWe'd like to thank vampire000 for reporting this issue. For more informationIf you have any questions or comments about this advisory:
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.4.0
1.5.0
1.6.0
1.6.1
1.6.2
+ 11 more Show less
1.6.3
1.6.4
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
Fixed in
2.5.4
References
Updated Jul 08, 2026 · Source: OSV.dev |
1.1.0
minor
Dependencies (17)
+ 9 more
Changelog
Compare changes
|
|
1.0.0
initial
1 CVE
CVE-2021-41274
GHSA-xm34-v85h-9pg2
Nov 18, 2021
Authentication Bypass by CSRF Weakness
9.3
/ 10
Critical
Network
Low
None
Required
Changed
High
High
None
ImpactCSRF vulnerability that allows user account takeover. All applications using any version of the frontend component of
That means that applications that haven't been configured differently from what it's generated with Rails aren't affected. PatchesUsers should promptly update to WorkaroundsA couple of options:
ReferencesThanksWe'd like to thank vampire000 for reporting this issue. For more informationIf you have any questions or comments about this advisory:
Affected versions
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.4.0
1.5.0
1.6.0
1.6.1
1.6.2
+ 11 more Show less
1.6.3
1.6.4
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.5.3
Fixed in
2.5.4
References
Updated Jul 08, 2026 · Source: OSV.dev |
1.0.0
initial
Dependencies (17)
+ 9 more
Changelog
|