spree_auth_devise
Provides authentication and authorization services for use with Spree by using Devise and CanCan.
Activity
- Latest release
- 2y ago
- Total releases
- 41
- Cadence
- ~32 days
- Last 12 months
- 0
Details
- License
- BSD-3-Clause
- First release
- Nov 08, 2012
| Version | Released | |
|---|---|---|
4.6.3
patch
| ||
4.6.2
patch
| ||
4.6.1
patch
| ||
4.6.0
minor
| ||
4.5.0
minor
| ||
4.4.2
patch
| ||
4.0.1
patch
|
4.0.1
patch
Dependencies (25)
+ 17 more
Changelog
Compare changes
|
|
4.2.1
patch
|
4.2.1
patch
Dependencies (6)
Changelog
Compare changes
|
|
4.1.1
patch
|
4.1.1
patch
Dependencies (28)
+ 20 more
Changelog
Compare changes
|
|
4.4.1
patch
| ||
4.4.0
minor
1 CVE
CVE-2021-41275
GHSA-26xx-m4q2-xhq8
Nov 18, 2021
Spree Auth Devise vulnerability allows for authentication bypass through CSRF weakness
9.3
/ 10
Critical
Network
Low
None
Required
Changed
High
High
None
ImpactCSRF vulnerability that allows user account takeover. All applications using any version of the frontend component of
That means that applications that haven't been configured differently from what it's generated with Rails aren't affected. Thanks @waiting-for-dev for reporting and providing a patch 👏 PatchesSpree 4.3 users should update to spree_auth_devise 4.4.1 Spree 4.2 users should update to spree_auth_devise 4.2.1 Spree 4.1 users should update to spree_auth_devise 4.1.1 Older Spree version users should update to spree_auth_devise 4.0.1 WorkaroundsIf possible, change your strategy to :exception:
Add the following to
Referenceshttps://github.com/solidusio/solidus_auth_devise/security/advisories/GHSA-xm34-v85h-9pg2 Affected versions
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.4.0
4.2.0
4.1.0
1.0.0
1.0.1
1.2.0
1.3.1
+ 18 more Show less
3.0.5
3.0.6
3.1.0
3.2.0
3.2.0.beta
3.3.0
3.3.0.rc1
3.3.1
3.3.3
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
4.0.0
4.0.0.rc1
4.0.0.rc2
Fixed in
4.0.1
4.1.1
4.2.1
4.4.1
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
4.3.4
patch
1 CVE
CVE-2021-41275
GHSA-26xx-m4q2-xhq8
Nov 18, 2021
Spree Auth Devise vulnerability allows for authentication bypass through CSRF weakness
9.3
/ 10
Critical
Network
Low
None
Required
Changed
High
High
None
ImpactCSRF vulnerability that allows user account takeover. All applications using any version of the frontend component of
That means that applications that haven't been configured differently from what it's generated with Rails aren't affected. Thanks @waiting-for-dev for reporting and providing a patch 👏 PatchesSpree 4.3 users should update to spree_auth_devise 4.4.1 Spree 4.2 users should update to spree_auth_devise 4.2.1 Spree 4.1 users should update to spree_auth_devise 4.1.1 Older Spree version users should update to spree_auth_devise 4.0.1 WorkaroundsIf possible, change your strategy to :exception:
Add the following to
Referenceshttps://github.com/solidusio/solidus_auth_devise/security/advisories/GHSA-xm34-v85h-9pg2 Affected versions
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.4.0
4.2.0
4.1.0
1.0.0
1.0.1
1.2.0
1.3.1
+ 18 more Show less
3.0.5
3.0.6
3.1.0
3.2.0
3.2.0.beta
3.3.0
3.3.0.rc1
3.3.1
3.3.3
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
4.0.0
4.0.0.rc1
4.0.0.rc2
Fixed in
4.0.1
4.1.1
4.2.1
4.4.1
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
4.3.3
patch
1 CVE
CVE-2021-41275
GHSA-26xx-m4q2-xhq8
Nov 18, 2021
Spree Auth Devise vulnerability allows for authentication bypass through CSRF weakness
9.3
/ 10
Critical
Network
Low
None
Required
Changed
High
High
None
ImpactCSRF vulnerability that allows user account takeover. All applications using any version of the frontend component of
That means that applications that haven't been configured differently from what it's generated with Rails aren't affected. Thanks @waiting-for-dev for reporting and providing a patch 👏 PatchesSpree 4.3 users should update to spree_auth_devise 4.4.1 Spree 4.2 users should update to spree_auth_devise 4.2.1 Spree 4.1 users should update to spree_auth_devise 4.1.1 Older Spree version users should update to spree_auth_devise 4.0.1 WorkaroundsIf possible, change your strategy to :exception:
Add the following to
Referenceshttps://github.com/solidusio/solidus_auth_devise/security/advisories/GHSA-xm34-v85h-9pg2 Affected versions
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.4.0
4.2.0
4.1.0
1.0.0
1.0.1
1.2.0
1.3.1
+ 18 more Show less
3.0.5
3.0.6
3.1.0
3.2.0
3.2.0.beta
3.3.0
3.3.0.rc1
3.3.1
3.3.3
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
4.0.0
4.0.0.rc1
4.0.0.rc2
Fixed in
4.0.1
4.1.1
4.2.1
4.4.1
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
4.3.2
patch
1 CVE
CVE-2021-41275
GHSA-26xx-m4q2-xhq8
Nov 18, 2021
Spree Auth Devise vulnerability allows for authentication bypass through CSRF weakness
9.3
/ 10
Critical
Network
Low
None
Required
Changed
High
High
None
ImpactCSRF vulnerability that allows user account takeover. All applications using any version of the frontend component of
That means that applications that haven't been configured differently from what it's generated with Rails aren't affected. Thanks @waiting-for-dev for reporting and providing a patch 👏 PatchesSpree 4.3 users should update to spree_auth_devise 4.4.1 Spree 4.2 users should update to spree_auth_devise 4.2.1 Spree 4.1 users should update to spree_auth_devise 4.1.1 Older Spree version users should update to spree_auth_devise 4.0.1 WorkaroundsIf possible, change your strategy to :exception:
Add the following to
Referenceshttps://github.com/solidusio/solidus_auth_devise/security/advisories/GHSA-xm34-v85h-9pg2 Affected versions
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.4.0
4.2.0
4.1.0
1.0.0
1.0.1
1.2.0
1.3.1
+ 18 more Show less
3.0.5
3.0.6
3.1.0
3.2.0
3.2.0.beta
3.3.0
3.3.0.rc1
3.3.1
3.3.3
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
4.0.0
4.0.0.rc1
4.0.0.rc2
Fixed in
4.0.1
4.1.1
4.2.1
4.4.1
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
4.3.1
patch
1 CVE
CVE-2021-41275
GHSA-26xx-m4q2-xhq8
Nov 18, 2021
Spree Auth Devise vulnerability allows for authentication bypass through CSRF weakness
9.3
/ 10
Critical
Network
Low
None
Required
Changed
High
High
None
ImpactCSRF vulnerability that allows user account takeover. All applications using any version of the frontend component of
That means that applications that haven't been configured differently from what it's generated with Rails aren't affected. Thanks @waiting-for-dev for reporting and providing a patch 👏 PatchesSpree 4.3 users should update to spree_auth_devise 4.4.1 Spree 4.2 users should update to spree_auth_devise 4.2.1 Spree 4.1 users should update to spree_auth_devise 4.1.1 Older Spree version users should update to spree_auth_devise 4.0.1 WorkaroundsIf possible, change your strategy to :exception:
Add the following to
Referenceshttps://github.com/solidusio/solidus_auth_devise/security/advisories/GHSA-xm34-v85h-9pg2 Affected versions
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.4.0
4.2.0
4.1.0
1.0.0
1.0.1
1.2.0
1.3.1
+ 18 more Show less
3.0.5
3.0.6
3.1.0
3.2.0
3.2.0.beta
3.3.0
3.3.0.rc1
3.3.1
3.3.3
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
4.0.0
4.0.0.rc1
4.0.0.rc2
Fixed in
4.0.1
4.1.1
4.2.1
4.4.1
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
4.3.0
minor
1 CVE
CVE-2021-41275
GHSA-26xx-m4q2-xhq8
Nov 18, 2021
Spree Auth Devise vulnerability allows for authentication bypass through CSRF weakness
9.3
/ 10
Critical
Network
Low
None
Required
Changed
High
High
None
ImpactCSRF vulnerability that allows user account takeover. All applications using any version of the frontend component of
That means that applications that haven't been configured differently from what it's generated with Rails aren't affected. Thanks @waiting-for-dev for reporting and providing a patch 👏 PatchesSpree 4.3 users should update to spree_auth_devise 4.4.1 Spree 4.2 users should update to spree_auth_devise 4.2.1 Spree 4.1 users should update to spree_auth_devise 4.1.1 Older Spree version users should update to spree_auth_devise 4.0.1 WorkaroundsIf possible, change your strategy to :exception:
Add the following to
Referenceshttps://github.com/solidusio/solidus_auth_devise/security/advisories/GHSA-xm34-v85h-9pg2 Affected versions
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.4.0
4.2.0
4.1.0
1.0.0
1.0.1
1.2.0
1.3.1
+ 18 more Show less
3.0.5
3.0.6
3.1.0
3.2.0
3.2.0.beta
3.3.0
3.3.0.rc1
3.3.1
3.3.3
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
4.0.0
4.0.0.rc1
4.0.0.rc2
Fixed in
4.0.1
4.1.1
4.2.1
4.4.1
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
4.2.0
minor
1 CVE
CVE-2021-41275
GHSA-26xx-m4q2-xhq8
Nov 18, 2021
Spree Auth Devise vulnerability allows for authentication bypass through CSRF weakness
9.3
/ 10
Critical
Network
Low
None
Required
Changed
High
High
None
ImpactCSRF vulnerability that allows user account takeover. All applications using any version of the frontend component of
That means that applications that haven't been configured differently from what it's generated with Rails aren't affected. Thanks @waiting-for-dev for reporting and providing a patch 👏 PatchesSpree 4.3 users should update to spree_auth_devise 4.4.1 Spree 4.2 users should update to spree_auth_devise 4.2.1 Spree 4.1 users should update to spree_auth_devise 4.1.1 Older Spree version users should update to spree_auth_devise 4.0.1 WorkaroundsIf possible, change your strategy to :exception:
Add the following to
Referenceshttps://github.com/solidusio/solidus_auth_devise/security/advisories/GHSA-xm34-v85h-9pg2 Affected versions
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.4.0
4.2.0
4.1.0
1.0.0
1.0.1
1.2.0
1.3.1
+ 18 more Show less
3.0.5
3.0.6
3.1.0
3.2.0
3.2.0.beta
3.3.0
3.3.0.rc1
3.3.1
3.3.3
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
4.0.0
4.0.0.rc1
4.0.0.rc2
Fixed in
4.0.1
4.1.1
4.2.1
4.4.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
4.2.0
minor
Dependencies (6)
Changelog
Compare changes
|
|
4.1.0
minor
1 CVE
CVE-2021-41275
GHSA-26xx-m4q2-xhq8
Nov 18, 2021
Spree Auth Devise vulnerability allows for authentication bypass through CSRF weakness
9.3
/ 10
Critical
Network
Low
None
Required
Changed
High
High
None
ImpactCSRF vulnerability that allows user account takeover. All applications using any version of the frontend component of
That means that applications that haven't been configured differently from what it's generated with Rails aren't affected. Thanks @waiting-for-dev for reporting and providing a patch 👏 PatchesSpree 4.3 users should update to spree_auth_devise 4.4.1 Spree 4.2 users should update to spree_auth_devise 4.2.1 Spree 4.1 users should update to spree_auth_devise 4.1.1 Older Spree version users should update to spree_auth_devise 4.0.1 WorkaroundsIf possible, change your strategy to :exception:
Add the following to
Referenceshttps://github.com/solidusio/solidus_auth_devise/security/advisories/GHSA-xm34-v85h-9pg2 Affected versions
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.4.0
4.2.0
4.1.0
1.0.0
1.0.1
1.2.0
1.3.1
+ 18 more Show less
3.0.5
3.0.6
3.1.0
3.2.0
3.2.0.beta
3.3.0
3.3.0.rc1
3.3.1
3.3.3
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
4.0.0
4.0.0.rc1
4.0.0.rc2
Fixed in
4.0.1
4.1.1
4.2.1
4.4.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
4.1.0
minor
Dependencies (28)
+ 20 more
Changelog
Compare changes
|
|
4.1.0.rc1
pre
|
4.1.0.rc1
pre
Dependencies (28)
+ 20 more
Changelog
Compare changes
|
|
4.0.0
major
1 CVE
CVE-2021-41275
GHSA-26xx-m4q2-xhq8
Nov 18, 2021
Spree Auth Devise vulnerability allows for authentication bypass through CSRF weakness
9.3
/ 10
Critical
Network
Low
None
Required
Changed
High
High
None
ImpactCSRF vulnerability that allows user account takeover. All applications using any version of the frontend component of
That means that applications that haven't been configured differently from what it's generated with Rails aren't affected. Thanks @waiting-for-dev for reporting and providing a patch 👏 PatchesSpree 4.3 users should update to spree_auth_devise 4.4.1 Spree 4.2 users should update to spree_auth_devise 4.2.1 Spree 4.1 users should update to spree_auth_devise 4.1.1 Older Spree version users should update to spree_auth_devise 4.0.1 WorkaroundsIf possible, change your strategy to :exception:
Add the following to
Referenceshttps://github.com/solidusio/solidus_auth_devise/security/advisories/GHSA-xm34-v85h-9pg2 Affected versions
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.4.0
4.2.0
4.1.0
1.0.0
1.0.1
1.2.0
1.3.1
+ 18 more Show less
3.0.5
3.0.6
3.1.0
3.2.0
3.2.0.beta
3.3.0
3.3.0.rc1
3.3.1
3.3.3
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
4.0.0
4.0.0.rc1
4.0.0.rc2
Fixed in
4.0.1
4.1.1
4.2.1
4.4.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
4.0.0
major
Dependencies (25)
+ 17 more
Changelog
Compare changes
|
|
4.0.0.rc2
pre
1 CVE
CVE-2021-41275
GHSA-26xx-m4q2-xhq8
Nov 18, 2021
Spree Auth Devise vulnerability allows for authentication bypass through CSRF weakness
9.3
/ 10
Critical
Network
Low
None
Required
Changed
High
High
None
ImpactCSRF vulnerability that allows user account takeover. All applications using any version of the frontend component of
That means that applications that haven't been configured differently from what it's generated with Rails aren't affected. Thanks @waiting-for-dev for reporting and providing a patch 👏 PatchesSpree 4.3 users should update to spree_auth_devise 4.4.1 Spree 4.2 users should update to spree_auth_devise 4.2.1 Spree 4.1 users should update to spree_auth_devise 4.1.1 Older Spree version users should update to spree_auth_devise 4.0.1 WorkaroundsIf possible, change your strategy to :exception:
Add the following to
Referenceshttps://github.com/solidusio/solidus_auth_devise/security/advisories/GHSA-xm34-v85h-9pg2 Affected versions
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.4.0
4.2.0
4.1.0
1.0.0
1.0.1
1.2.0
1.3.1
+ 18 more Show less
3.0.5
3.0.6
3.1.0
3.2.0
3.2.0.beta
3.3.0
3.3.0.rc1
3.3.1
3.3.3
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
4.0.0
4.0.0.rc1
4.0.0.rc2
Fixed in
4.0.1
4.1.1
4.2.1
4.4.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
4.0.0.rc2
pre
Dependencies (25)
+ 17 more
Changelog
Compare changes
|
|
4.0.0.rc1
pre
1 CVE
CVE-2021-41275
GHSA-26xx-m4q2-xhq8
Nov 18, 2021
Spree Auth Devise vulnerability allows for authentication bypass through CSRF weakness
9.3
/ 10
Critical
Network
Low
None
Required
Changed
High
High
None
ImpactCSRF vulnerability that allows user account takeover. All applications using any version of the frontend component of
That means that applications that haven't been configured differently from what it's generated with Rails aren't affected. Thanks @waiting-for-dev for reporting and providing a patch 👏 PatchesSpree 4.3 users should update to spree_auth_devise 4.4.1 Spree 4.2 users should update to spree_auth_devise 4.2.1 Spree 4.1 users should update to spree_auth_devise 4.1.1 Older Spree version users should update to spree_auth_devise 4.0.1 WorkaroundsIf possible, change your strategy to :exception:
Add the following to
Referenceshttps://github.com/solidusio/solidus_auth_devise/security/advisories/GHSA-xm34-v85h-9pg2 Affected versions
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.4.0
4.2.0
4.1.0
1.0.0
1.0.1
1.2.0
1.3.1
+ 18 more Show less
3.0.5
3.0.6
3.1.0
3.2.0
3.2.0.beta
3.3.0
3.3.0.rc1
3.3.1
3.3.3
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
4.0.0
4.0.0.rc1
4.0.0.rc2
Fixed in
4.0.1
4.1.1
4.2.1
4.4.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
4.0.0.rc1
pre
Dependencies (25)
+ 17 more
Changelog
Compare changes
|
|
3.5.2
patch
1 CVE
CVE-2021-41275
GHSA-26xx-m4q2-xhq8
Nov 18, 2021
Spree Auth Devise vulnerability allows for authentication bypass through CSRF weakness
9.3
/ 10
Critical
Network
Low
None
Required
Changed
High
High
None
ImpactCSRF vulnerability that allows user account takeover. All applications using any version of the frontend component of
That means that applications that haven't been configured differently from what it's generated with Rails aren't affected. Thanks @waiting-for-dev for reporting and providing a patch 👏 PatchesSpree 4.3 users should update to spree_auth_devise 4.4.1 Spree 4.2 users should update to spree_auth_devise 4.2.1 Spree 4.1 users should update to spree_auth_devise 4.1.1 Older Spree version users should update to spree_auth_devise 4.0.1 WorkaroundsIf possible, change your strategy to :exception:
Add the following to
Referenceshttps://github.com/solidusio/solidus_auth_devise/security/advisories/GHSA-xm34-v85h-9pg2 Affected versions
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.4.0
4.2.0
4.1.0
1.0.0
1.0.1
1.2.0
1.3.1
+ 18 more Show less
3.0.5
3.0.6
3.1.0
3.2.0
3.2.0.beta
3.3.0
3.3.0.rc1
3.3.1
3.3.3
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
4.0.0
4.0.0.rc1
4.0.0.rc2
Fixed in
4.0.1
4.1.1
4.2.1
4.4.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
3.5.2
patch
Dependencies (24)
+ 16 more
Changelog
Compare changes
|
|
3.5.1
patch
1 CVE
CVE-2021-41275
GHSA-26xx-m4q2-xhq8
Nov 18, 2021
Spree Auth Devise vulnerability allows for authentication bypass through CSRF weakness
9.3
/ 10
Critical
Network
Low
None
Required
Changed
High
High
None
ImpactCSRF vulnerability that allows user account takeover. All applications using any version of the frontend component of
That means that applications that haven't been configured differently from what it's generated with Rails aren't affected. Thanks @waiting-for-dev for reporting and providing a patch 👏 PatchesSpree 4.3 users should update to spree_auth_devise 4.4.1 Spree 4.2 users should update to spree_auth_devise 4.2.1 Spree 4.1 users should update to spree_auth_devise 4.1.1 Older Spree version users should update to spree_auth_devise 4.0.1 WorkaroundsIf possible, change your strategy to :exception:
Add the following to
Referenceshttps://github.com/solidusio/solidus_auth_devise/security/advisories/GHSA-xm34-v85h-9pg2 Affected versions
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.4.0
4.2.0
4.1.0
1.0.0
1.0.1
1.2.0
1.3.1
+ 18 more Show less
3.0.5
3.0.6
3.1.0
3.2.0
3.2.0.beta
3.3.0
3.3.0.rc1
3.3.1
3.3.3
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
4.0.0
4.0.0.rc1
4.0.0.rc2
Fixed in
4.0.1
4.1.1
4.2.1
4.4.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
3.5.1
patch
Dependencies (24)
+ 16 more
Changelog
Compare changes
|
|
3.5.0
minor
1 CVE
CVE-2021-41275
GHSA-26xx-m4q2-xhq8
Nov 18, 2021
Spree Auth Devise vulnerability allows for authentication bypass through CSRF weakness
9.3
/ 10
Critical
Network
Low
None
Required
Changed
High
High
None
ImpactCSRF vulnerability that allows user account takeover. All applications using any version of the frontend component of
That means that applications that haven't been configured differently from what it's generated with Rails aren't affected. Thanks @waiting-for-dev for reporting and providing a patch 👏 PatchesSpree 4.3 users should update to spree_auth_devise 4.4.1 Spree 4.2 users should update to spree_auth_devise 4.2.1 Spree 4.1 users should update to spree_auth_devise 4.1.1 Older Spree version users should update to spree_auth_devise 4.0.1 WorkaroundsIf possible, change your strategy to :exception:
Add the following to
Referenceshttps://github.com/solidusio/solidus_auth_devise/security/advisories/GHSA-xm34-v85h-9pg2 Affected versions
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.4.0
4.2.0
4.1.0
1.0.0
1.0.1
1.2.0
1.3.1
+ 18 more Show less
3.0.5
3.0.6
3.1.0
3.2.0
3.2.0.beta
3.3.0
3.3.0.rc1
3.3.1
3.3.3
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
4.0.0
4.0.0.rc1
4.0.0.rc2
Fixed in
4.0.1
4.1.1
4.2.1
4.4.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
3.5.0
minor
Dependencies (24)
+ 16 more
Changelog
Compare changes
|
|
3.4.2
patch
1 CVE
CVE-2021-41275
GHSA-26xx-m4q2-xhq8
Nov 18, 2021
Spree Auth Devise vulnerability allows for authentication bypass through CSRF weakness
9.3
/ 10
Critical
Network
Low
None
Required
Changed
High
High
None
ImpactCSRF vulnerability that allows user account takeover. All applications using any version of the frontend component of
That means that applications that haven't been configured differently from what it's generated with Rails aren't affected. Thanks @waiting-for-dev for reporting and providing a patch 👏 PatchesSpree 4.3 users should update to spree_auth_devise 4.4.1 Spree 4.2 users should update to spree_auth_devise 4.2.1 Spree 4.1 users should update to spree_auth_devise 4.1.1 Older Spree version users should update to spree_auth_devise 4.0.1 WorkaroundsIf possible, change your strategy to :exception:
Add the following to
Referenceshttps://github.com/solidusio/solidus_auth_devise/security/advisories/GHSA-xm34-v85h-9pg2 Affected versions
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.4.0
4.2.0
4.1.0
1.0.0
1.0.1
1.2.0
1.3.1
+ 18 more Show less
3.0.5
3.0.6
3.1.0
3.2.0
3.2.0.beta
3.3.0
3.3.0.rc1
3.3.1
3.3.3
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
4.0.0
4.0.0.rc1
4.0.0.rc2
Fixed in
4.0.1
4.1.1
4.2.1
4.4.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
3.4.2
patch
Dependencies (23)
+ 15 more
Changelog
Compare changes
|
|
3.4.1
patch
1 CVE
CVE-2021-41275
GHSA-26xx-m4q2-xhq8
Nov 18, 2021
Spree Auth Devise vulnerability allows for authentication bypass through CSRF weakness
9.3
/ 10
Critical
Network
Low
None
Required
Changed
High
High
None
ImpactCSRF vulnerability that allows user account takeover. All applications using any version of the frontend component of
That means that applications that haven't been configured differently from what it's generated with Rails aren't affected. Thanks @waiting-for-dev for reporting and providing a patch 👏 PatchesSpree 4.3 users should update to spree_auth_devise 4.4.1 Spree 4.2 users should update to spree_auth_devise 4.2.1 Spree 4.1 users should update to spree_auth_devise 4.1.1 Older Spree version users should update to spree_auth_devise 4.0.1 WorkaroundsIf possible, change your strategy to :exception:
Add the following to
Referenceshttps://github.com/solidusio/solidus_auth_devise/security/advisories/GHSA-xm34-v85h-9pg2 Affected versions
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.4.0
4.2.0
4.1.0
1.0.0
1.0.1
1.2.0
1.3.1
+ 18 more Show less
3.0.5
3.0.6
3.1.0
3.2.0
3.2.0.beta
3.3.0
3.3.0.rc1
3.3.1
3.3.3
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
4.0.0
4.0.0.rc1
4.0.0.rc2
Fixed in
4.0.1
4.1.1
4.2.1
4.4.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
3.4.1
patch
Dependencies (23)
+ 15 more
Changelog
Compare changes
|
|
3.4.0
minor
1 CVE
CVE-2021-41275
GHSA-26xx-m4q2-xhq8
Nov 18, 2021
Spree Auth Devise vulnerability allows for authentication bypass through CSRF weakness
9.3
/ 10
Critical
Network
Low
None
Required
Changed
High
High
None
ImpactCSRF vulnerability that allows user account takeover. All applications using any version of the frontend component of
That means that applications that haven't been configured differently from what it's generated with Rails aren't affected. Thanks @waiting-for-dev for reporting and providing a patch 👏 PatchesSpree 4.3 users should update to spree_auth_devise 4.4.1 Spree 4.2 users should update to spree_auth_devise 4.2.1 Spree 4.1 users should update to spree_auth_devise 4.1.1 Older Spree version users should update to spree_auth_devise 4.0.1 WorkaroundsIf possible, change your strategy to :exception:
Add the following to
Referenceshttps://github.com/solidusio/solidus_auth_devise/security/advisories/GHSA-xm34-v85h-9pg2 Affected versions
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.4.0
4.2.0
4.1.0
1.0.0
1.0.1
1.2.0
1.3.1
+ 18 more Show less
3.0.5
3.0.6
3.1.0
3.2.0
3.2.0.beta
3.3.0
3.3.0.rc1
3.3.1
3.3.3
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
4.0.0
4.0.0.rc1
4.0.0.rc2
Fixed in
4.0.1
4.1.1
4.2.1
4.4.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
3.4.0
minor
Dependencies (23)
+ 15 more
Changelog
Compare changes
|
|
3.3.3
patch
1 CVE
CVE-2021-41275
GHSA-26xx-m4q2-xhq8
Nov 18, 2021
Spree Auth Devise vulnerability allows for authentication bypass through CSRF weakness
9.3
/ 10
Critical
Network
Low
None
Required
Changed
High
High
None
ImpactCSRF vulnerability that allows user account takeover. All applications using any version of the frontend component of
That means that applications that haven't been configured differently from what it's generated with Rails aren't affected. Thanks @waiting-for-dev for reporting and providing a patch 👏 PatchesSpree 4.3 users should update to spree_auth_devise 4.4.1 Spree 4.2 users should update to spree_auth_devise 4.2.1 Spree 4.1 users should update to spree_auth_devise 4.1.1 Older Spree version users should update to spree_auth_devise 4.0.1 WorkaroundsIf possible, change your strategy to :exception:
Add the following to
Referenceshttps://github.com/solidusio/solidus_auth_devise/security/advisories/GHSA-xm34-v85h-9pg2 Affected versions
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.4.0
4.2.0
4.1.0
1.0.0
1.0.1
1.2.0
1.3.1
+ 18 more Show less
3.0.5
3.0.6
3.1.0
3.2.0
3.2.0.beta
3.3.0
3.3.0.rc1
3.3.1
3.3.3
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
4.0.0
4.0.0.rc1
4.0.0.rc2
Fixed in
4.0.1
4.1.1
4.2.1
4.4.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
3.3.3
patch
Dependencies (23)
+ 15 more
Changelog
Compare changes
|
|
3.3.1
patch
1 CVE
CVE-2021-41275
GHSA-26xx-m4q2-xhq8
Nov 18, 2021
Spree Auth Devise vulnerability allows for authentication bypass through CSRF weakness
9.3
/ 10
Critical
Network
Low
None
Required
Changed
High
High
None
ImpactCSRF vulnerability that allows user account takeover. All applications using any version of the frontend component of
That means that applications that haven't been configured differently from what it's generated with Rails aren't affected. Thanks @waiting-for-dev for reporting and providing a patch 👏 PatchesSpree 4.3 users should update to spree_auth_devise 4.4.1 Spree 4.2 users should update to spree_auth_devise 4.2.1 Spree 4.1 users should update to spree_auth_devise 4.1.1 Older Spree version users should update to spree_auth_devise 4.0.1 WorkaroundsIf possible, change your strategy to :exception:
Add the following to
Referenceshttps://github.com/solidusio/solidus_auth_devise/security/advisories/GHSA-xm34-v85h-9pg2 Affected versions
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.4.0
4.2.0
4.1.0
1.0.0
1.0.1
1.2.0
1.3.1
+ 18 more Show less
3.0.5
3.0.6
3.1.0
3.2.0
3.2.0.beta
3.3.0
3.3.0.rc1
3.3.1
3.3.3
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
4.0.0
4.0.0.rc1
4.0.0.rc2
Fixed in
4.0.1
4.1.1
4.2.1
4.4.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
3.3.1
patch
Dependencies (23)
+ 15 more
Changelog
Compare changes
|
|
3.3.0
minor
1 CVE
CVE-2021-41275
GHSA-26xx-m4q2-xhq8
Nov 18, 2021
Spree Auth Devise vulnerability allows for authentication bypass through CSRF weakness
9.3
/ 10
Critical
Network
Low
None
Required
Changed
High
High
None
ImpactCSRF vulnerability that allows user account takeover. All applications using any version of the frontend component of
That means that applications that haven't been configured differently from what it's generated with Rails aren't affected. Thanks @waiting-for-dev for reporting and providing a patch 👏 PatchesSpree 4.3 users should update to spree_auth_devise 4.4.1 Spree 4.2 users should update to spree_auth_devise 4.2.1 Spree 4.1 users should update to spree_auth_devise 4.1.1 Older Spree version users should update to spree_auth_devise 4.0.1 WorkaroundsIf possible, change your strategy to :exception:
Add the following to
Referenceshttps://github.com/solidusio/solidus_auth_devise/security/advisories/GHSA-xm34-v85h-9pg2 Affected versions
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.4.0
4.2.0
4.1.0
1.0.0
1.0.1
1.2.0
1.3.1
+ 18 more Show less
3.0.5
3.0.6
3.1.0
3.2.0
3.2.0.beta
3.3.0
3.3.0.rc1
3.3.1
3.3.3
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
4.0.0
4.0.0.rc1
4.0.0.rc2
Fixed in
4.0.1
4.1.1
4.2.1
4.4.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
3.3.0
minor
Dependencies (23)
+ 15 more
Changelog
Compare changes
|
|
3.3.0.rc1
pre
1 CVE
CVE-2021-41275
GHSA-26xx-m4q2-xhq8
Nov 18, 2021
Spree Auth Devise vulnerability allows for authentication bypass through CSRF weakness
9.3
/ 10
Critical
Network
Low
None
Required
Changed
High
High
None
ImpactCSRF vulnerability that allows user account takeover. All applications using any version of the frontend component of
That means that applications that haven't been configured differently from what it's generated with Rails aren't affected. Thanks @waiting-for-dev for reporting and providing a patch 👏 PatchesSpree 4.3 users should update to spree_auth_devise 4.4.1 Spree 4.2 users should update to spree_auth_devise 4.2.1 Spree 4.1 users should update to spree_auth_devise 4.1.1 Older Spree version users should update to spree_auth_devise 4.0.1 WorkaroundsIf possible, change your strategy to :exception:
Add the following to
Referenceshttps://github.com/solidusio/solidus_auth_devise/security/advisories/GHSA-xm34-v85h-9pg2 Affected versions
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.4.0
4.2.0
4.1.0
1.0.0
1.0.1
1.2.0
1.3.1
+ 18 more Show less
3.0.5
3.0.6
3.1.0
3.2.0
3.2.0.beta
3.3.0
3.3.0.rc1
3.3.1
3.3.3
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
4.0.0
4.0.0.rc1
4.0.0.rc2
Fixed in
4.0.1
4.1.1
4.2.1
4.4.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
3.3.0.rc1
pre
Dependencies (23)
+ 15 more
Changelog
Compare changes
|
|
3.2.0
minor
1 CVE
CVE-2021-41275
GHSA-26xx-m4q2-xhq8
Nov 18, 2021
Spree Auth Devise vulnerability allows for authentication bypass through CSRF weakness
9.3
/ 10
Critical
Network
Low
None
Required
Changed
High
High
None
ImpactCSRF vulnerability that allows user account takeover. All applications using any version of the frontend component of
That means that applications that haven't been configured differently from what it's generated with Rails aren't affected. Thanks @waiting-for-dev for reporting and providing a patch 👏 PatchesSpree 4.3 users should update to spree_auth_devise 4.4.1 Spree 4.2 users should update to spree_auth_devise 4.2.1 Spree 4.1 users should update to spree_auth_devise 4.1.1 Older Spree version users should update to spree_auth_devise 4.0.1 WorkaroundsIf possible, change your strategy to :exception:
Add the following to
Referenceshttps://github.com/solidusio/solidus_auth_devise/security/advisories/GHSA-xm34-v85h-9pg2 Affected versions
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.4.0
4.2.0
4.1.0
1.0.0
1.0.1
1.2.0
1.3.1
+ 18 more Show less
3.0.5
3.0.6
3.1.0
3.2.0
3.2.0.beta
3.3.0
3.3.0.rc1
3.3.1
3.3.3
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
4.0.0
4.0.0.rc1
4.0.0.rc2
Fixed in
4.0.1
4.1.1
4.2.1
4.4.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
3.2.0
minor
Dependencies (22)
+ 14 more
Changelog
Compare changes
|
|
3.2.0.beta
pre
1 CVE
CVE-2021-41275
GHSA-26xx-m4q2-xhq8
Nov 18, 2021
Spree Auth Devise vulnerability allows for authentication bypass through CSRF weakness
9.3
/ 10
Critical
Network
Low
None
Required
Changed
High
High
None
ImpactCSRF vulnerability that allows user account takeover. All applications using any version of the frontend component of
That means that applications that haven't been configured differently from what it's generated with Rails aren't affected. Thanks @waiting-for-dev for reporting and providing a patch 👏 PatchesSpree 4.3 users should update to spree_auth_devise 4.4.1 Spree 4.2 users should update to spree_auth_devise 4.2.1 Spree 4.1 users should update to spree_auth_devise 4.1.1 Older Spree version users should update to spree_auth_devise 4.0.1 WorkaroundsIf possible, change your strategy to :exception:
Add the following to
Referenceshttps://github.com/solidusio/solidus_auth_devise/security/advisories/GHSA-xm34-v85h-9pg2 Affected versions
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.4.0
4.2.0
4.1.0
1.0.0
1.0.1
1.2.0
1.3.1
+ 18 more Show less
3.0.5
3.0.6
3.1.0
3.2.0
3.2.0.beta
3.3.0
3.3.0.rc1
3.3.1
3.3.3
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
4.0.0
4.0.0.rc1
4.0.0.rc2
Fixed in
4.0.1
4.1.1
4.2.1
4.4.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
3.2.0.beta
pre
Dependencies (22)
+ 14 more
Changelog
Compare changes
|
|
3.1.0
minor
1 CVE
CVE-2021-41275
GHSA-26xx-m4q2-xhq8
Nov 18, 2021
Spree Auth Devise vulnerability allows for authentication bypass through CSRF weakness
9.3
/ 10
Critical
Network
Low
None
Required
Changed
High
High
None
ImpactCSRF vulnerability that allows user account takeover. All applications using any version of the frontend component of
That means that applications that haven't been configured differently from what it's generated with Rails aren't affected. Thanks @waiting-for-dev for reporting and providing a patch 👏 PatchesSpree 4.3 users should update to spree_auth_devise 4.4.1 Spree 4.2 users should update to spree_auth_devise 4.2.1 Spree 4.1 users should update to spree_auth_devise 4.1.1 Older Spree version users should update to spree_auth_devise 4.0.1 WorkaroundsIf possible, change your strategy to :exception:
Add the following to
Referenceshttps://github.com/solidusio/solidus_auth_devise/security/advisories/GHSA-xm34-v85h-9pg2 Affected versions
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.4.0
4.2.0
4.1.0
1.0.0
1.0.1
1.2.0
1.3.1
+ 18 more Show less
3.0.5
3.0.6
3.1.0
3.2.0
3.2.0.beta
3.3.0
3.3.0.rc1
3.3.1
3.3.3
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
4.0.0
4.0.0.rc1
4.0.0.rc2
Fixed in
4.0.1
4.1.1
4.2.1
4.4.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
3.1.0
minor
Dependencies (20)
+ 12 more
Changelog
Compare changes
|
|
3.0.6
patch
1 CVE
CVE-2021-41275
GHSA-26xx-m4q2-xhq8
Nov 18, 2021
Spree Auth Devise vulnerability allows for authentication bypass through CSRF weakness
9.3
/ 10
Critical
Network
Low
None
Required
Changed
High
High
None
ImpactCSRF vulnerability that allows user account takeover. All applications using any version of the frontend component of
That means that applications that haven't been configured differently from what it's generated with Rails aren't affected. Thanks @waiting-for-dev for reporting and providing a patch 👏 PatchesSpree 4.3 users should update to spree_auth_devise 4.4.1 Spree 4.2 users should update to spree_auth_devise 4.2.1 Spree 4.1 users should update to spree_auth_devise 4.1.1 Older Spree version users should update to spree_auth_devise 4.0.1 WorkaroundsIf possible, change your strategy to :exception:
Add the following to
Referenceshttps://github.com/solidusio/solidus_auth_devise/security/advisories/GHSA-xm34-v85h-9pg2 Affected versions
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.4.0
4.2.0
4.1.0
1.0.0
1.0.1
1.2.0
1.3.1
+ 18 more Show less
3.0.5
3.0.6
3.1.0
3.2.0
3.2.0.beta
3.3.0
3.3.0.rc1
3.3.1
3.3.3
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
4.0.0
4.0.0.rc1
4.0.0.rc2
Fixed in
4.0.1
4.1.1
4.2.1
4.4.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
3.0.6
patch
Dependencies (23)
+ 15 more
Changelog
Compare changes
|
|
3.0.5
major
1 CVE
CVE-2021-41275
GHSA-26xx-m4q2-xhq8
Nov 18, 2021
Spree Auth Devise vulnerability allows for authentication bypass through CSRF weakness
9.3
/ 10
Critical
Network
Low
None
Required
Changed
High
High
None
ImpactCSRF vulnerability that allows user account takeover. All applications using any version of the frontend component of
That means that applications that haven't been configured differently from what it's generated with Rails aren't affected. Thanks @waiting-for-dev for reporting and providing a patch 👏 PatchesSpree 4.3 users should update to spree_auth_devise 4.4.1 Spree 4.2 users should update to spree_auth_devise 4.2.1 Spree 4.1 users should update to spree_auth_devise 4.1.1 Older Spree version users should update to spree_auth_devise 4.0.1 WorkaroundsIf possible, change your strategy to :exception:
Add the following to
Referenceshttps://github.com/solidusio/solidus_auth_devise/security/advisories/GHSA-xm34-v85h-9pg2 Affected versions
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.4.0
4.2.0
4.1.0
1.0.0
1.0.1
1.2.0
1.3.1
+ 18 more Show less
3.0.5
3.0.6
3.1.0
3.2.0
3.2.0.beta
3.3.0
3.3.0.rc1
3.3.1
3.3.3
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
4.0.0
4.0.0.rc1
4.0.0.rc2
Fixed in
4.0.1
4.1.1
4.2.1
4.4.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
3.0.5
major
Dependencies (23)
+ 15 more
Changelog
Compare changes
|
|
1.3.1
minor
2 CVEs
CVE-2013-2506
GHSA-jp57-9j37-5476
May 17, 2022
spree_auth_devise allows remote authenticated users to assign themselves arbitrary roles
Medium
Affected versions
1.0.0
1.0.1
1.2.0
1.3.1
Fixed in
3.0.5
References
Updated Dec 07, 2024 · Source: OSV.dev
CVE-2021-41275
GHSA-26xx-m4q2-xhq8
Nov 18, 2021
Spree Auth Devise vulnerability allows for authentication bypass through CSRF weakness
9.3
/ 10
Critical
Network
Low
None
Required
Changed
High
High
None
ImpactCSRF vulnerability that allows user account takeover. All applications using any version of the frontend component of
That means that applications that haven't been configured differently from what it's generated with Rails aren't affected. Thanks @waiting-for-dev for reporting and providing a patch 👏 PatchesSpree 4.3 users should update to spree_auth_devise 4.4.1 Spree 4.2 users should update to spree_auth_devise 4.2.1 Spree 4.1 users should update to spree_auth_devise 4.1.1 Older Spree version users should update to spree_auth_devise 4.0.1 WorkaroundsIf possible, change your strategy to :exception:
Add the following to
Referenceshttps://github.com/solidusio/solidus_auth_devise/security/advisories/GHSA-xm34-v85h-9pg2 Affected versions
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.4.0
4.2.0
4.1.0
1.0.0
1.0.1
1.2.0
1.3.1
+ 18 more Show less
3.0.5
3.0.6
3.1.0
3.2.0
3.2.0.beta
3.3.0
3.3.0.rc1
3.3.1
3.3.3
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
4.0.0
4.0.0.rc1
4.0.0.rc2
Fixed in
4.0.1
4.1.1
4.2.1
4.4.1
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
1.2.0
minor
2 CVEs
CVE-2013-2506
GHSA-jp57-9j37-5476
May 17, 2022
spree_auth_devise allows remote authenticated users to assign themselves arbitrary roles
Medium
Affected versions
1.0.0
1.0.1
1.2.0
1.3.1
Fixed in
3.0.5
References
Updated Dec 07, 2024 · Source: OSV.dev
CVE-2021-41275
GHSA-26xx-m4q2-xhq8
Nov 18, 2021
Spree Auth Devise vulnerability allows for authentication bypass through CSRF weakness
9.3
/ 10
Critical
Network
Low
None
Required
Changed
High
High
None
ImpactCSRF vulnerability that allows user account takeover. All applications using any version of the frontend component of
That means that applications that haven't been configured differently from what it's generated with Rails aren't affected. Thanks @waiting-for-dev for reporting and providing a patch 👏 PatchesSpree 4.3 users should update to spree_auth_devise 4.4.1 Spree 4.2 users should update to spree_auth_devise 4.2.1 Spree 4.1 users should update to spree_auth_devise 4.1.1 Older Spree version users should update to spree_auth_devise 4.0.1 WorkaroundsIf possible, change your strategy to :exception:
Add the following to
Referenceshttps://github.com/solidusio/solidus_auth_devise/security/advisories/GHSA-xm34-v85h-9pg2 Affected versions
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.4.0
4.2.0
4.1.0
1.0.0
1.0.1
1.2.0
1.3.1
+ 18 more Show less
3.0.5
3.0.6
3.1.0
3.2.0
3.2.0.beta
3.3.0
3.3.0.rc1
3.3.1
3.3.3
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
4.0.0
4.0.0.rc1
4.0.0.rc2
Fixed in
4.0.1
4.1.1
4.2.1
4.4.1
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
1.0.1
patch
2 CVEs
CVE-2013-2506
GHSA-jp57-9j37-5476
May 17, 2022
spree_auth_devise allows remote authenticated users to assign themselves arbitrary roles
Medium
Affected versions
1.0.0
1.0.1
1.2.0
1.3.1
Fixed in
3.0.5
References
Updated Dec 07, 2024 · Source: OSV.dev
CVE-2021-41275
GHSA-26xx-m4q2-xhq8
Nov 18, 2021
Spree Auth Devise vulnerability allows for authentication bypass through CSRF weakness
9.3
/ 10
Critical
Network
Low
None
Required
Changed
High
High
None
ImpactCSRF vulnerability that allows user account takeover. All applications using any version of the frontend component of
That means that applications that haven't been configured differently from what it's generated with Rails aren't affected. Thanks @waiting-for-dev for reporting and providing a patch 👏 PatchesSpree 4.3 users should update to spree_auth_devise 4.4.1 Spree 4.2 users should update to spree_auth_devise 4.2.1 Spree 4.1 users should update to spree_auth_devise 4.1.1 Older Spree version users should update to spree_auth_devise 4.0.1 WorkaroundsIf possible, change your strategy to :exception:
Add the following to
Referenceshttps://github.com/solidusio/solidus_auth_devise/security/advisories/GHSA-xm34-v85h-9pg2 Affected versions
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.4.0
4.2.0
4.1.0
1.0.0
1.0.1
1.2.0
1.3.1
+ 18 more Show less
3.0.5
3.0.6
3.1.0
3.2.0
3.2.0.beta
3.3.0
3.3.0.rc1
3.3.1
3.3.3
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
4.0.0
4.0.0.rc1
4.0.0.rc2
Fixed in
4.0.1
4.1.1
4.2.1
4.4.1
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
1.0.0
initial
2 CVEs
CVE-2013-2506
GHSA-jp57-9j37-5476
May 17, 2022
spree_auth_devise allows remote authenticated users to assign themselves arbitrary roles
Medium
Affected versions
1.0.0
1.0.1
1.2.0
1.3.1
Fixed in
3.0.5
References
Updated Dec 07, 2024 · Source: OSV.dev
CVE-2021-41275
GHSA-26xx-m4q2-xhq8
Nov 18, 2021
Spree Auth Devise vulnerability allows for authentication bypass through CSRF weakness
9.3
/ 10
Critical
Network
Low
None
Required
Changed
High
High
None
ImpactCSRF vulnerability that allows user account takeover. All applications using any version of the frontend component of
That means that applications that haven't been configured differently from what it's generated with Rails aren't affected. Thanks @waiting-for-dev for reporting and providing a patch 👏 PatchesSpree 4.3 users should update to spree_auth_devise 4.4.1 Spree 4.2 users should update to spree_auth_devise 4.2.1 Spree 4.1 users should update to spree_auth_devise 4.1.1 Older Spree version users should update to spree_auth_devise 4.0.1 WorkaroundsIf possible, change your strategy to :exception:
Add the following to
Referenceshttps://github.com/solidusio/solidus_auth_devise/security/advisories/GHSA-xm34-v85h-9pg2 Affected versions
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.4.0
4.2.0
4.1.0
1.0.0
1.0.1
1.2.0
1.3.1
+ 18 more Show less
3.0.5
3.0.6
3.1.0
3.2.0
3.2.0.beta
3.3.0
3.3.0.rc1
3.3.1
3.3.3
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
4.0.0
4.0.0.rc1
4.0.0.rc2
Fixed in
4.0.1
4.1.1
4.2.1
4.4.1
References
Updated Jul 08, 2026 · Source: OSV.dev |