SECURITY ANNOUNCEMENT: We've just released solidus...
# general
w
SECURITY ANNOUNCEMENT: We've just released solidus_auth_devise 2.5.4 to fix a severe security vulnerability (account takeover by CSRF attack). Please, look at https://github.com/solidusio/solidus_auth_devise/security/advisories/GHSA-xm34-v85h-9pg2 for details, and also for workarounds in case you aren't able to update straight away. We want to thank @Severin and https://www.on-running.com/ for catching and reporting it to us 🙌 🙌
k
Please be aware that if you are on Spree, all their versions of
spree_auth_devise
have the same vulnerability. Of course, we reported this to our friends over there before the disclosure and I’m sure they are working on a fix.
p
🙌 spree just released fixes too
k
🎉
r
The GitHub notice thanks a HackerOne account for the discovery. What is the timeline to the full disclosure?
k
Where are you seeing that?
w
Yeah, the user at HackerOne wanted to be credited through its HO account. @Robert Stewart, isn't it enough for you with the GH security advisory? If possible, we'd like to have a single source of information for the issue.
r
@waiting_for_dev The GH advisory has a “For more information” section that suggests contacting the core team here. I am happy to re-ask (and explain) my question wherever is most helpful. Where would be best?
w
Does Slack work for you? You can send me a private message if you prefer. Otherwise, you can contact me at marcbusque@nebulab.com
r
@waiting_for_dev I’ll send you a private message and you can repost the information wherever is best.