Описание
As a result of an incomplete fix for CVE-2015-7225, in versions of devise-two-factor prior to 4.0.2 it is possible to reuse a One-Time-Password (OTP) for one (and only one) immediately trailing interval. CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N)
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | DNE | |
| devel | DNE | |
| esm-apps/focal | released | 3.1.0-2ubuntu0.1~esm1 |
| esm-apps/jammy | released | 4.0.0-2ubuntu0.1~esm1 |
| esm-apps/noble | not-affected | 4.0.2-1 |
| esm-apps/xenial | needed | |
| focal | ignored | end of standard support, was needed |
| impish | ignored | end of life |
| jammy | needed | |
| kinetic | ignored | end of life, was needed |
Показывать по
Ссылки на источники
EPSS
3.5 Low
CVSS2
5.3 Medium
CVSS3
Связанные уязвимости
As a result of an incomplete fix for CVE-2015-7225, in versions of devise-two-factor prior to 4.0.2 it is possible to reuse a One-Time-Password (OTP) for one (and only one) immediately trailing interval. CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N)
As a result of an incomplete fix for CVE-2015-7225, in versions of dev ...
Improper one time password handling in devise-two-factor
EPSS
3.5 Low
CVSS2
5.3 Medium
CVSS3