Groups
Groups
Sign in
Groups
Groups
solidus-security
Conversations
About
Send feedback
Help
Group path
solidus-security
Contact owners and managers
1–29 of 29
Here we will be posting announcements about Solidus and Spree security vulnerabilities.
Sign up by email
Mark all as read
Report group
0 selected
Jared Norman
Oct 7
[solidus_storefront] [GHSA-mhwq-2v9w-r659] Storefront password reset endpoint allows for account enumeration
Versions Affected: All storefronts generated by `solidus:install` (Solidus Storefront, previously
unread,
[solidus_storefront] [GHSA-mhwq-2v9w-r659] Storefront password reset endpoint allows for account enumeration
Versions Affected: All storefronts generated by `solidus:install` (Solidus Storefront, previously
Oct 7
Jared Norman
Oct 7
[solidus_auth_devise] [GHSA-mc6q-7qq6-ghg8] Password reset endpoints allow for account enumeration
Versions Affected: All versions of solidus_auth_devise (<= 2.6.0) Not affected: NONE Fixed
unread,
[solidus_auth_devise] [GHSA-mc6q-7qq6-ghg8] Password reset endpoints allow for account enumeration
Versions Affected: All versions of solidus_auth_devise (<= 2.6.0) Not affected: NONE Fixed
Oct 7
Jared Norman
Oct 7
[solidus_frontend] [GHSA-87gm-56c6-255g] Stored cross-site scripting in Solidus Frontend order details
Versions Affected: All versions of solidus_frontend (<= 4.7.1), including releases published from
unread,
[solidus_frontend] [GHSA-87gm-56c6-255g] Stored cross-site scripting in Solidus Frontend order details
Versions Affected: All versions of solidus_frontend (<= 4.7.1), including releases published from
Oct 7
Jared Norman
Oct 7
[solidus_admin] [GHSA-3cfg-886h-22vf] Unrestricted type assignment in admin payment methods controller
Versions Affected: solidus_admin installed from the `main` branch on or after 2026-09-19 Not affected
unread,
[solidus_admin] [GHSA-3cfg-886h-22vf] Unrestricted type assignment in admin payment methods controller
Versions Affected: solidus_admin installed from the `main` branch on or after 2026-09-19 Not affected
Oct 7
Jared Norman
Oct 7
[solidus_admin] [GHSA-g9c8-3mxq-rpgh] Stored cross-site scripting in Solidus admin customer purchased items
Versions Affected: solidus_admin 0.3.0 through 0.4.0 Not affected: solidus_admin 0.2.0 and earlier;
unread,
[solidus_admin] [GHSA-g9c8-3mxq-rpgh] Stored cross-site scripting in Solidus admin customer purchased items
Versions Affected: solidus_admin 0.3.0 through 0.4.0 Not affected: solidus_admin 0.2.0 and earlier;
Oct 7
Jared Norman
Oct 7
[GHSA-vgwx-9pm9-8qvj] Customers can attach another user's stored gateway payment profile to their own payment
Versions Affected: All versions of Solidus Not affected: NONE Fixed Versions: 4.7.2, 4.6.4 Impact ---
unread,
[GHSA-vgwx-9pm9-8qvj] Customers can attach another user's stored gateway payment profile to their own payment
Versions Affected: All versions of Solidus Not affected: NONE Fixed Versions: 4.7.2, 4.6.4 Impact ---
Oct 7
Jared Norman
Oct 7
[GHSA-qwqm-3jx5-rr8m] Checkout state skip via unvalidated state parameter
Versions Affected: All versions of Solidus (`solidus_api`) Not affected: NONE Fixed Versions: 4.7.2,
unread,
[GHSA-qwqm-3jx5-rr8m] Checkout state skip via unvalidated state parameter
Versions Affected: All versions of Solidus (`solidus_api`) Not affected: NONE Fixed Versions: 4.7.2,
Oct 7
Jared Norman
Oct 7
[GHSA-6p7r-vx57-9gw3] Missing authorization check on return item inventory units allows cancelling other customers' returns
Versions Affected: All versions of Solidus Not affected: NONE Fixed Versions: 4.7.2, 4.6.4 Impact ---
unread,
[GHSA-6p7r-vx57-9gw3] Missing authorization check on return item inventory units allows cancelling other customers' returns
Versions Affected: All versions of Solidus Not affected: NONE Fixed Versions: 4.7.2, 4.6.4 Impact ---
Oct 7
Jared Norman
Oct 7
[GHSA-x943-j5hw-mr2w] Stored cross-site scripting in Solidus product descriptions
Versions Affected: All versions of Solidus (`solidus_core`) Not affected: NONE Fixed Versions: 4.7.2,
unread,
[GHSA-x943-j5hw-mr2w] Stored cross-site scripting in Solidus product descriptions
Versions Affected: All versions of Solidus (`solidus_core`) Not affected: NONE Fixed Versions: 4.7.2,
Oct 7
Jared Norman
Oct 7
[GHSA-rw5f-4cm4-pc4m] Users with UserManagement permissions can assign themselves the admin role or change an admin's password
Versions Affected: Solidus 3.2.2 and later (`solidus_core`); all versions of `solidus_api` Not
unread,
[GHSA-rw5f-4cm4-pc4m] Users with UserManagement permissions can assign themselves the admin role or change an admin's password
Versions Affected: Solidus 3.2.2 and later (`solidus_core`); all versions of `solidus_api` Not
Oct 7
Jared Norman
Sep 9
[solidus_frontend] [GHSA-qj34-2493-vx9f] Guest token fixation in Solidus Frontend enables cart takeover and order data disclosure
Versions Affected: All versions of solidus_frontend (<= 4.7.0), including releases published from
unread,
[solidus_frontend] [GHSA-qj34-2493-vx9f] Guest token fixation in Solidus Frontend enables cart takeover and order data disclosure
Versions Affected: All versions of solidus_frontend (<= 4.7.0), including releases published from
Sep 9
Jared Norman
Sep 9
[solidus_storefront] [GHSA-g82m-w3m9-rrwh] Guest token fixation in Solidus Storefront enables cart takeover and order data disclosure
Versions Affected: All storefronts generated by `solidus:install` since Solidus 3.2 (Solidus
unread,
[solidus_storefront] [GHSA-g82m-w3m9-rrwh] Guest token fixation in Solidus Storefront enables cart takeover and order data disclosure
Versions Affected: All storefronts generated by `solidus:install` since Solidus 3.2 (Solidus
Sep 9
Jared Norman
Sep 9
[GHSA-c2fq-w6qj-3hj4] Arbitrary payment amounts via the orders and payments APIs enable order underpayment
Versions Affected: All versions of Solidus Not affected: NONE Fixed Versions: 4.7.1, 4.6.3 Impact ---
unread,
[GHSA-c2fq-w6qj-3hj4] Arbitrary payment amounts via the orders and payments APIs enable order underpayment
Versions Affected: All versions of Solidus Not affected: NONE Fixed Versions: 4.7.1, 4.6.3 Impact ---
Sep 9
Jared Norman
Sep 9
[GHSA-92gv-2pxv-7gjg] Unauthenticated tampering with and disclosure of guest-checkout credit cards via nil-user ability
Versions Affected: All versions of Solidus (`solidus_api`) Not affected: NONE Fixed Versions: 4.7.1,
unread,
[GHSA-92gv-2pxv-7gjg] Unauthenticated tampering with and disclosure of guest-checkout credit cards via nil-user ability
Versions Affected: All versions of Solidus (`solidus_api`) Not affected: NONE Fixed Versions: 4.7.1,
Sep 9
marc
6/1/22
[GHSA-8639-qx56-r428] CSRF allows attacker to finalize/unfinalize order adjustments in solidus_backend
Versions Affected: All version of solidus_backend Not affected: NONE Fixed Versions: 3.1.6, 3.0.6,
unread,
[GHSA-8639-qx56-r428] CSRF allows attacker to finalize/unfinalize order adjustments in solidus_backend
Versions Affected: All version of solidus_backend Not affected: NONE Fixed Versions: 3.1.6, 3.0.6,
6/1/22
marc
12/20/21
[GHSA-h3fg-h5v3-vf8m] CSRF forgery protection bypass for Spree::OrdersController#populate
Versions Affected: All version of solidus_frontend Not affected: NONE Fixed Versions: 3.1.5, 3.0.5,
unread,
[GHSA-h3fg-h5v3-vf8m] CSRF forgery protection bypass for Spree::OrdersController#populate
Versions Affected: All version of solidus_frontend Not affected: NONE Fixed Versions: 3.1.5, 3.0.5,
12/20/21
marc
3
12/9/21
[GHSA-qxmr-qxh6-2cc9] ReDos vulnerability on guest checkout email validation
It seems that the offender here is the Google post-send (or pre-render) formatter... Anyway, no
unread,
[GHSA-qxmr-qxh6-2cc9] ReDos vulnerability on guest checkout email validation
It seems that the offender here is the Google post-send (or pre-render) formatter... Anyway, no
12/9/21
marc
11/17/21
[solidus_auth_devise] [GHSA-xm34-v85h-9pg2] Authentication Bypass by CSRF Weakness
Versions Affected: All version of solidus_auth_devise Not affected: NONE Fixed Versions: 2.5.4 Impact
unread,
[solidus_auth_devise] [GHSA-xm34-v85h-9pg2] Authentication Bypass by CSRF Weakness
Versions Affected: All version of solidus_auth_devise Not affected: NONE Fixed Versions: 2.5.4 Impact
11/17/21
Alberto Vena
7/16/20
[CVE-2020-15109] Ability to change order address without triggering address validations
Versions Affected: All version of Solidus Not affected: NONE Fixed Versions: 2.10.2, 2.9.6, 2.8.6 A
unread,
[CVE-2020-15109] Ability to change order address without triggering address validations
Versions Affected: All version of Solidus Not affected: NONE Fixed Versions: 2.10.2, 2.9.6, 2.8.6 A
7/16/20
John Hawthorn
12/12/17
Unsafe payment creation via API and frontend
Unsafe payment creation via API and frontend Versions Affected: All version of Solidus All version of
unread,
Unsafe payment creation via API and frontend
Unsafe payment creation via API and frontend Versions Affected: All version of Solidus All version of
12/12/17
John Hawthorn
7/24/17
Unauthenticated manipulation of payments in solidus_gateway
Unauthenticated manipulation of payments in solidus_gateway Versions Affected: solidus_gateway - all
unread,
Unauthenticated manipulation of payments in solidus_gateway
Unauthenticated manipulation of payments in solidus_gateway Versions Affected: solidus_gateway - all
7/24/17
John Hawthorn
2/23/16
Multiple possible admin XSS vulnerabilities
Multiple possible admin XSS vulnerabilities Versions Affected: All versions of Spree and Solidus Not
unread,
Multiple possible admin XSS vulnerabilities
Multiple possible admin XSS vulnerabilities Versions Affected: All versions of Spree and Solidus Not
2/23/16
John Hawthorn
2/23/16
Potential JSON hijacking in old browsers in the admin
Potential JSON hijacking in old browsers in the admin Versions Affected: All versions of Spree and
unread,
Potential JSON hijacking in old browsers in the admin
Potential JSON hijacking in old browsers in the admin Versions Affected: All versions of Spree and
2/23/16
John Hawthorn
2/23/16
Potential XSS on checkout address page
Versions Affected: All versions of Spree and Solidus Not affected: None. Fixed Versions: Solidus 1.0.
unread,
Potential XSS on checkout address page
Versions Affected: All versions of Spree and Solidus Not affected: None. Fixed Versions: Solidus 1.0.
2/23/16
John Hawthorn
2/23/16
XSS vulnerability in select2 in the admin
XSS vulnerability in select2 in the admin Versions Affected: All versions of Spree and Solidus Not
unread,
XSS vulnerability in select2 in the admin
XSS vulnerability in select2 in the admin Versions Affected: All versions of Spree and Solidus Not
2/23/16
John Hawthorn
1/25/16
Multiple CVEs in rails
Rails has announced multiple CVEs and has released a new version, 4.2.5.1. All users are advised to
unread,
Multiple CVEs in rails
Rails has announced multiple CVEs and has released a new version, 4.2.5.1. All users are advised to
1/25/16
John Hawthorn
8/19/15
Information disclosure vulnerability through Ransack searches
We've released 1.0.1, which includes this major security fix https://github.com/solidusio/solidus
unread,
Information disclosure vulnerability through Ransack searches
We've released 1.0.1, which includes this major security fix https://github.com/solidusio/solidus
8/19/15
John Hawthorn
7/28/15
Remote Code Execution and File Disclosure Vulnerability
Versions Affected: All versions of Spree and Solidus (introduced in Spree 1.2) Fixed Versions:
unread,
Remote Code Execution and File Disclosure Vulnerability
Versions Affected: All versions of Spree and Solidus (introduced in Spree 1.2) Fixed Versions:
7/28/15
John Hawthorn
7/21/15
Remote file system access vulnerability in API
Versions Affected: Spree 1.3 and later, Solidus 1.0.0.pre Fixed: Solidus 1.0.0.pre2 Impact ------ An
unread,
Remote file system access vulnerability in API
Versions Affected: Spree 1.3 and later, Solidus 1.0.0.pre Fixed: Solidus 1.0.0.pre2 Impact ------ An
7/21/15