Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jm35-h8q2-73mp

Опубликовано: 07 апр. 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

Improper one time password handling in devise-two-factor

Impact

As a result of an incomplete fix for CVE-2015-7225, in versions of devise-two-factor prior to 4.0.2 it is possible to reuse a One-Time-Password (OTP) for one (and only one) immediately trailing interval.

Patches

This vulnerability has been patched in version 4.0.2 which was released on March 24th, 2022. Individuals using this package are strongly encouraged to upgrade as soon as possible.

Credit for discovery

Benoit Côté-Jodoin Michael Nipper - https://github.com/tinfoil/devise-two-factor/issues/106

Пакеты

Наименование

devise-two-factor

rubygems
Затронутые версииВерсия исправления

< 4.0.2

4.0.2

EPSS

Процентиль: 59%
0.00386
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
почти 4 года назад

As a result of an incomplete fix for CVE-2015-7225, in versions of devise-two-factor prior to 4.0.2 it is possible to reuse a One-Time-Password (OTP) for one (and only one) immediately trailing interval. CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N)

CVSS3: 5.3
nvd
почти 4 года назад

As a result of an incomplete fix for CVE-2015-7225, in versions of devise-two-factor prior to 4.0.2 it is possible to reuse a One-Time-Password (OTP) for one (and only one) immediately trailing interval. CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N)

CVSS3: 5.3
debian
почти 4 года назад

As a result of an incomplete fix for CVE-2015-7225, in versions of dev ...

EPSS

Процентиль: 59%
0.00386
Низкий

5.3 Medium

CVSS3