Security Bypass Affecting devise package, versions >=2.2, <2.2.3>=2.1, <2.1.3>=1.6, <2.0.5<1.5.4


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
73.79% (99th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Security Bypass vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-RUBY-DEVISE-20055
  • published27 Jan 2013
  • disclosed27 Jan 2013
  • creditjoernchen

Introduced: 27 Jan 2013

CVE-2013-0233  (opens in a new tab)
CWE-284  (opens in a new tab)

Overview

devise is an authentication framework for Rails with Warden.

Affected versions allow an attacker to craft a malformed request in order to bypass security restrictions, potentially gaining control of other accounts. The vulnerability lies in a problematic type conversion of database queries against certain databases.

CVSS Scores

version 3.1