Логотип exploitDog
bind:CVE-2013-0233
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2013-0233

Количество 4

Количество 4

ubuntu логотип

CVE-2013-0233

почти 13 лет назад

Devise gem 2.2.x before 2.2.3, 2.1.x before 2.1.3, 2.0.x before 2.0.5, and 1.5.x before 1.5.4 for Ruby, when using certain databases, does not properly perform type conversion when performing database queries, which might allow remote attackers to cause incorrect results to be returned and bypass security checks via unknown vectors, as demonstrated by resetting passwords of arbitrary accounts.

CVSS2: 6.8
EPSS: Средний
nvd логотип

CVE-2013-0233

почти 13 лет назад

Devise gem 2.2.x before 2.2.3, 2.1.x before 2.1.3, 2.0.x before 2.0.5, and 1.5.x before 1.5.4 for Ruby, when using certain databases, does not properly perform type conversion when performing database queries, which might allow remote attackers to cause incorrect results to be returned and bypass security checks via unknown vectors, as demonstrated by resetting passwords of arbitrary accounts.

CVSS2: 6.8
EPSS: Средний
debian логотип

CVE-2013-0233

почти 13 лет назад

Devise gem 2.2.x before 2.2.3, 2.1.x before 2.1.3, 2.0.x before 2.0.5, ...

CVSS2: 6.8
EPSS: Средний
github логотип

GHSA-jxhw-mg8m-2pj8

больше 8 лет назад

Devise does not properly perform type conversion when performing database queries

EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2013-0233

Devise gem 2.2.x before 2.2.3, 2.1.x before 2.1.3, 2.0.x before 2.0.5, and 1.5.x before 1.5.4 for Ruby, when using certain databases, does not properly perform type conversion when performing database queries, which might allow remote attackers to cause incorrect results to be returned and bypass security checks via unknown vectors, as demonstrated by resetting passwords of arbitrary accounts.

CVSS2: 6.8
69%
Средний
почти 13 лет назад
nvd логотип
CVE-2013-0233

Devise gem 2.2.x before 2.2.3, 2.1.x before 2.1.3, 2.0.x before 2.0.5, and 1.5.x before 1.5.4 for Ruby, when using certain databases, does not properly perform type conversion when performing database queries, which might allow remote attackers to cause incorrect results to be returned and bypass security checks via unknown vectors, as demonstrated by resetting passwords of arbitrary accounts.

CVSS2: 6.8
69%
Средний
почти 13 лет назад
debian логотип
CVE-2013-0233

Devise gem 2.2.x before 2.2.3, 2.1.x before 2.1.3, 2.0.x before 2.0.5, ...

CVSS2: 6.8
69%
Средний
почти 13 лет назад
github логотип
GHSA-jxhw-mg8m-2pj8

Devise does not properly perform type conversion when performing database queries

69%
Средний
больше 8 лет назад

Уязвимостей на страницу