CRITICAL9.3RubyGems
GHSA-26xx-m4q2-xhq8· CVE-2021-41275Spree Auth Devise vulnerability allows for authentication bypass through CSRF weakness
Modified: 7/8/2026
package
pkg:rubygems/spree_auth_devise
Spree Auth Devise vulnerability allows for authentication bypass through CSRF weakness
Modified: 7/8/2026
spree_auth_devise allows remote authenticated users to assign themselves arbitrary roles
Modified: 12/7/2024