{"id":"CVE-2021-43846","aliases":["GHSA-h3fg-h5v3-vf8m"],"url":"https://o3.security/vulnerability/CVE-2021-43846","summary":"CSRF forgery protection bypass in solidus_frontend","details":"`solidus_frontend` is the cart and storefront for the Solidus e-commerce project. Versions of `solidus_frontend` prior to 3.1.5, 3.0.5, and 2.11.14 contain a cross-site request forgery (CSRF) vulnerability that allows a malicious site to add an item to the user's cart without their knowledge. Versions 3.1.5, 3.0.5, and 2.11.14 contain a patch for this issue. The patch adds CSRF token verification to the \"Add to cart\" action. Adding forgery protection to a form that missed it can have some side effects. Other CSRF protection strategies as well as a workaround involving modifcation to config/application.rb` are available. More details on these mitigations are available in the GitHub Security Advisory.","published":"2021-12-20T22:15:07.947Z","modified":"2026-07-09T11:24:16.483289Z","cvss":{"score":4.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"},"epss":{"score":0.00575,"percentile":0.44813,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"RubyGems","name":"solidus_frontend","fixedVersion":"2.11.14"},{"ecosystem":"RubyGems","name":"solidus_frontend","fixedVersion":"3.0.5"},{"ecosystem":"RubyGems","name":"solidus_frontend","fixedVersion":"3.1.5"}],"fix":{"url":"https://github.com/solidusio/solidus/commit/4d17cacf066d9492fc04eb3a0b16084b47376d81","label":"solidusio/solidus@4d17cac"},"references":[{"type":"FIX","url":"https://github.com/solidusio/solidus/commit/4d17cacf066d9492fc04eb3a0b16084b47376d81"},{"type":"FIX","url":"https://github.com/solidusio/solidus/commit/a1b9bf7f24f9b8684fc4d943eacb02b1926c77c6"},{"type":"EVIDENCE","url":"https://github.com/solidusio/solidus/security/advisories/GHSA-h3fg-h5v3-vf8m"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-09T11:24:16.483289Z"}}