CVE-2021-41274 is a high-severity (CVSS 8.8) Cross-Site Request Forgery (CSRF) vulnerability in solidus_auth_devise. 1 public exploit reference exists, so weaponization risk is real. A fix is available for solidus_auth_devise — see the affected versions and patch details below.
Authentication Bypass by CSRF Weakness
EPSS Exploitation Probability
Probability of exploitation in the next 30 days, from FIRST.org EPSS.
How urgent is this, really
CVE-2021-41274 by exploitation likelihood (EPSS) against impact (CVSS). Outside the shaded patch-first corner.
Where this sits among everything scored
Of 385,738 CVEs with a current EPSS score, this one falls in the < 10% band (highlighted). Counts from FIRST.org, log-scaled.
Real-World Exposure
solidus_auth_deviseReal-time download stats are indexed for npm and PyPI packages. This vulnerability affects RubyGems packages — download data is not available via public APIs for these ecosystems.
Description
Impact
CSRF vulnerability that allows user account takeover.
All applications using any version of the frontend component of solidus_auth_devise are affected if protect_from_forgery method is both:
- Executed whether as:
- A
before_actioncallback (the default) - A
prepend_before_action(optionprepend: truegiven) before the:load_objecthook inSpree::UserController(most likely order to find).
- A
- Configured to use
:null_sessionor:reset_sessionstrategies (:null_sessionis the default in case the no strategy is given, butrails --newgenerated skeleton use:exception).
That means that applications that haven't been configured differently from what it's generated with Rails aren't affected.
Patches
Users should promptly update to solidus_auth_devise version 2.5.4.
Workarounds
A couple of options:
-
If possible, change your strategy to
:exception:class ApplicationController < ActionController::Base protect_from_forgery with: :exception end -
Add the following to
config/application.rbto at least run the:exceptionstrategy on the affected controller:config.after_initialize do Spree::UsersController.protect_from_forgery with: :exception end -
We've also released new Solidus versions monkey patching
solidus_auth_devisewith the quick fix. Those versions arev3.1.3,v.3.0.3&v2.11.12. See GHSA-5629-8855-gf4g for details.
References
Thanks
We'd like to thank vampire000 for reporting this issue.
For more information
If you have any questions or comments about this advisory:
- Open an issue in solidus_auth_devise or a discussion in solidus
- Email us at [email protected]
- Contact the core team on Slack
Affected Packages
| Ecosystem | Package | Vulnerable range | Fix |
|---|---|---|---|
| 💎RubyGems | solidus_auth_devise | ≥ 1.0.0&&< 2.5.4 | 2.5.4bundle update solidus_auth_devise --conservative |
Affected Products
solidus auth devisenebulabResearch use only. For defensive security, authorized penetration testing, and academic research only. Never execute exploit code against systems without explicit written authorization.
Detection & mitigation playbook
Open-source dependencyDetect
Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for solidus_auth_devise, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.
Fix
Update solidus_auth_devise to 2.5.4 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms CVE-2021-41274 is resolved across your whole dependency graph.
Workarounds
If you can't upgrade right away: gate or disable the affected feature, validate untrusted input at the boundary, and avoid passing attacker-controlled data into the vulnerable path. O3's runtime protection blocks exploitation in production as an interim safeguard until the upgrade lands.
Frequently Asked Questions
Is CVE-2021-41274 in your dependencies?
Find it across RubyGems, including transitive dependencies.