Security Bypass Affecting devise package, versions >=2.2, <2.2.3 >=2.1, <2.1.3 >=1.6, <2.0.5 <1.5.4
Threat Intelligence
EPSS
9.8% (96th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-RUBY-DEVISE-20055
- published 27 Jan 2013
- disclosed 27 Jan 2013
- credit joernchen
Introduced: 27 Jan 2013
CVE-2013-0233 Open this link in a new tabOverview
devise
is an authentication framework for Rails with Warden.
Affected versions allow an attacker to craft a malformed request in order to bypass security restrictions, potentially gaining control of other accounts. The vulnerability lies in a problematic type conversion of database queries against certain databases.
CVSS Scores
version 3.1