GHSA-26xx-m4q2-xhq8
Spree Auth Devise vulnerability allows for authentication bypass through CSRF weakness
Quick fix
GHSA-26xx-m4q2-xhq8 — spree_auth_devise: upgrade to the fixed version with the command below.
bundle update spree_auth_deviseDetails
### Impact
CSRF vulnerability that allows user account takeover.
All applications using any version of the frontend component of `spree_auth_devise` are affected if `protect_from_forgery` method is both:
* Executed whether as: * A before_action callback (the default) * A prepend_before_action (option prepend: true given) before the :load_object hook in Spree::UserController (most likely order to find). * Configured to use :null_session or :reset_session strategies (:null_session is the default in case the no strategy is given, but rails --new generated skeleton use :exception).
That means that applications that haven't been configured differently from what it's generated with Rails aren't affected.
Thanks @waiting-for-dev for reporting and providing a patch 👏
### Patches
Spree 4.3 users should update to spree_auth_devise 4.4.1 Spree 4.2 users should update to spree_auth_devise 4.2.1 Spree 4.1 users should update to spree_auth_devise 4.1.1 Older Spree version users should update to spree_auth_devise 4.0.1 ### Workarounds
If possible, change your strategy to :exception:
```ruby class ApplicationController < ActionController::Base protect_from_forgery with: :exception end ```
Add the following to`config/application.rb `to at least run the `:exception` strategy on the affected controller:
```ruby config.after_initialize do Spree::UsersController.protect_from_forgery with: :exception end ```
### References https://github.com/solidusio/solidus_auth_devise/security/advisories/GHSA-xm34-v85h-9pg2
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/solidusio/solidus_auth_devise/security/advisories/GHSA-xm34-v85h-9pg2[WEB]
- https://github.com/spree/spree_auth_devise/security/advisories/GHSA-26xx-m4q2-xhq8[WEB]
- https://github.com/spree/spree_auth_devise/security/advisories/GHSA-6mqr-q86q-6gwr[WEB]
- https://github.com/spree/spree_auth_devise/security/advisories/GHSA-8xfw-5q82-3652[WEB]
- https://github.com/spree/spree_auth_devise/security/advisories/GHSA-gpqc-4pp7-5954[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2021-41275[ADVISORY]
- https://github.com/spree/spree_auth_devise/commit/adf6ed4cd94d66091776b5febd4ff3767362de63[WEB]
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/spree_auth_devise/CVE-2021-41275.yml[WEB]
- https://github.com/spree/spree_auth_devise[PACKAGE]