{"id":"CVE-2021-43846","details":"`solidus_frontend` is the cart and storefront for the Solidus e-commerce project. Versions of `solidus_frontend` prior to 3.1.5, 3.0.5, and 2.11.14 contain a cross-site request forgery (CSRF) vulnerability that allows a malicious site to add an item to the user's cart without their knowledge. Versions 3.1.5, 3.0.5, and 2.11.14 contain a patch for this issue. The patch adds CSRF token verification to the \"Add to cart\" action. Adding forgery protection to a form that missed it can have some side effects. Other CSRF protection strategies as well as a workaround involving modifcation to config/application.rb` are available. More details on these mitigations are available in the GitHub Security Advisory.","aliases":["GHSA-h3fg-h5v3-vf8m"],"modified":"2026-07-09T11:24:16.483289Z","published":"2021-12-20T22:15:07.947Z","references":[{"type":"FIX","url":"https://github.com/solidusio/solidus/commit/4d17cacf066d9492fc04eb3a0b16084b47376d81"},{"type":"FIX","url":"https://github.com/solidusio/solidus/commit/a1b9bf7f24f9b8684fc4d943eacb02b1926c77c6"},{"type":"EVIDENCE","url":"https://github.com/solidusio/solidus/security/advisories/GHSA-h3fg-h5v3-vf8m"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/solidusio/solidus","events":[{"introduced":"0"},{"fixed":"3e94658398ab019ab3e7aa4357862bac92dd06d0"},{"introduced":"a731a1a7bede0b7cd012551c27ebdd74e08c022a"},{"fixed":"0ae44e82554ac83b4a00cd2609fc9537f088b398"},{"introduced":"1e06d430ba17c8ac092ddb00f23b38eb5c062b80"},{"fixed":"8981fdfcb0f3ecc302508455ce2d3ad41dec309a"},{"fixed":"4d17cacf066d9492fc04eb3a0b16084b47376d81"},{"fixed":"a1b9bf7f24f9b8684fc4d943eacb02b1926c77c6"}],"database_specific":{"cpe":"cpe:2.3:a:nebulab:solidus:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"2.11.14"},{"introduced":"3.0.0"},{"fixed":"3.0.5"},{"introduced":"3.1.0"},{"fixed":"3.1.5"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["v3.1.4","v2.11.13","v3.0.4","v2.11.12","v3.0.3","v3.1.3","v2.11.11","v3.0.2","v3.1.2","v3.1.1","v3.1.0","v2.11.10","v3.0.1","v3.0.0","v2.11.9","v2.11.8","v2.11.7","v2.11.6","v2.11.5","v3.0.0.rc2","v2.11.4","v2.11.3","v2.11.2","v2.11.1","v2.11.0","v2.10.0.beta1","v2.9.0.rc.1","v2.7.0","v2.0.0.beta1","v1.1.0.pre2","v1.1.0.beta1","v1.0.0.pre3","v1.0.0.pre2","v1.0.0.pre"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-43846.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"}]}