Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fcjw-8rhj-gwwc

Опубликовано: 11 сент. 2019
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

Authentication Bypass in Devise

An issue was discovered in Plataformatec Devise before 4.7.1. It confirms accounts upon receiving a request with a blank confirmation_token, if a database record has a blank value in the confirmation_token column. (However, there is no scenario within Devise itself in which such database records would exist.)

Пакеты

Наименование

devise

rubygems
Затронутые версииВерсия исправления

< 4.7.1

4.7.1

EPSS

Процентиль: 53%
0.00297
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 6 лет назад

An issue was discovered in Plataformatec Devise before 4.7.1. It confirms accounts upon receiving a request with a blank confirmation_token, if a database record has a blank value in the confirmation_token column. (However, there is no scenario within Devise itself in which such database records would exist.)

CVSS3: 5.3
nvd
больше 6 лет назад

An issue was discovered in Plataformatec Devise before 4.7.1. It confirms accounts upon receiving a request with a blank confirmation_token, if a database record has a blank value in the confirmation_token column. (However, there is no scenario within Devise itself in which such database records would exist.)

EPSS

Процентиль: 53%
0.00297
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-284