Описание
Devise Gem for Ruby Unauthorized Access Using "Remember Me" Cookie
Devise version before 3.5.4 uses cookies to implement a "Remember me" functionality. However, it generates the same cookie for all devices. If an attacker manages to steal a remember me cookie and the user does not change the password frequently, the cookie can be used to gain access to the application indefinitely.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2015-8314
- https://github.com/heartcombo/devise/commit/c92996646aba2d25b2c3e235fe0c4f1a84b70d24
- https://github.com/advisories/GHSA-746g-3gfp-hfhw
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/devise/CVE-2015-8314.yml
- https://rubysec.com/advisories/CVE-2015-8314
- http://blog.plataformatec.com.br/2016/01/improve-remember-me-cookie-expiration-in-devise
Пакеты
Наименование
devise
rubygems
Затронутые версииВерсия исправления
< 3.5.4
3.5.4
Связанные уязвимости
CVSS3: 7.5
nvd
около 2 лет назад
The Devise gem before 3.5.4 for Ruby mishandles Remember Me cookies for sessions, which may allow an adversary to obtain unauthorized persistent application access.
CVSS3: 7.5
debian
около 2 лет назад
The Devise gem before 3.5.4 for Ruby mishandles Remember Me cookies fo ...