trestle-auth
Authentication plugin for the Trestle admin framework
Activity
- Latest release
- 2y ago
- Total releases
- 15
- Cadence
- ~5 months
- Last 12 months
- 0
Details
- License
- unknown
- First release
- Jul 31, 2017
| Version | Released | |
|---|---|---|
0.5.0
minor
| ||
0.5.0.pre2
pre
| ||
0.5.0.pre
pre
| ||
0.4.4
patch
| ||
0.4.3
patch
| ||
0.4.2
patch
| ||
0.4.1
patch
1 CVE
CVE-2021-29435
GHSA-h8hx-2c5r-32cf
Apr 13, 2021
Cross-Site Request Forgery (CSRF) in trestle-auth
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
ImpactA vulnerability in trestle-auth versions 0.4.0 and 0.4.1 allows an attacker to create a form that will bypass Rails' built-in CSRF protection when submitted by a victim with a trestle-auth admin session. This potentially allows an attacker to alter protected data, including admin account credentials. PatchesThe vulnerability has been fixed in trestle-auth 0.4.2 released to RubyGems. For more informationIf you have any questions or comments about this advisory:
Affected versions
0.4.0
0.4.1
Fixed in
0.4.2
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.4.0
minor
1 CVE
CVE-2021-29435
GHSA-h8hx-2c5r-32cf
Apr 13, 2021
Cross-Site Request Forgery (CSRF) in trestle-auth
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
ImpactA vulnerability in trestle-auth versions 0.4.0 and 0.4.1 allows an attacker to create a form that will bypass Rails' built-in CSRF protection when submitted by a victim with a trestle-auth admin session. This potentially allows an attacker to alter protected data, including admin account credentials. PatchesThe vulnerability has been fixed in trestle-auth 0.4.2 released to RubyGems. For more informationIf you have any questions or comments about this advisory:
Affected versions
0.4.0
0.4.1
Fixed in
0.4.2
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.3.0
minor
| ||
0.2.5
patch
| ||
0.2.4
patch
| ||
0.2.3
patch
| ||
0.2.2
patch
| ||
0.2.1
patch
| ||
0.2.0
initial
|