VYPR

Solidus Auth Devise

by Nebulab

CVEs (1)

  • CVE-2021-41274CriNov 17, 2021
    risk 0.53cvss 9.3epss 0.01

    solidus_auth_devise provides authentication services for the Solidus webstore framework, using the Devise gem. In affected versions solidus_auth_devise is subject to a CSRF vulnerability that allows user account takeover. All applications using any version of the frontend…