Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-746g-3gfp-hfhw

Опубликовано: 26 янв. 2023
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Devise Gem for Ruby Unauthorized Access Using "Remember Me" Cookie

Devise version before 3.5.4 uses cookies to implement a "Remember me" functionality. However, it generates the same cookie for all devices. If an attacker manages to steal a remember me cookie and the user does not change the password frequently, the cookie can be used to gain access to the application indefinitely.

Пакеты

Наименование

devise

rubygems
Затронутые версииВерсия исправления

< 3.5.4

3.5.4

EPSS

Процентиль: 34%
0.00139
Низкий

7.5 High

CVSS3

Дефекты

CWE-288
CWE-312

Связанные уязвимости

CVSS3: 7.5
nvd
около 2 лет назад

The Devise gem before 3.5.4 for Ruby mishandles Remember Me cookies for sessions, which may allow an adversary to obtain unauthorized persistent application access.

CVSS3: 7.5
debian
около 2 лет назад

The Devise gem before 3.5.4 for Ruby mishandles Remember Me cookies fo ...

EPSS

Процентиль: 34%
0.00139
Низкий

7.5 High

CVSS3

Дефекты

CWE-288
CWE-312