5 Total advisories
5 Vulnerabilities
0 Malware
Dependency scanning
Check whether spree_auth_devise is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CRITICAL 9.3
CVE-2021-41275
Spree Auth Devise vulnerability allows for authentication bypass through CSRF weakness
CRITICAL 9.3
GHSA-gpqc-4pp7-5954
Duplicate Advisory: Authentication Bypass by CSRF Weakness
CRITICAL 9.3
GHSA-6mqr-q86q-6gwr
Duplicate Advisory: Authentication Bypass by CSRF Weakness
CRITICAL 9.3
GHSA-8xfw-5q82-3652
Duplicate Advisory: Authentication Bypass by CSRF Weakness
UNKNOWN
CVE-2013-2506
spree_auth_devise allows remote authenticated users to assign themselves arbitrary roles
Browse more RubyGems advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes