CSRF Token Fixation Affecting devise package, versions >=2.3, <3.0.1<2.2.5


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about CSRF Token Fixation vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-RUBY-DEVISE-20103
  • published1 Aug 2013
  • disclosed1 Aug 2013
  • creditEgor Homakov

Introduced: 1 Aug 2013

CVE NOT AVAILABLE CWE-352  (opens in a new tab)

Overview

devise is an authentication framework for Rails with Warden.

Affected versions contain a flaw that allows a remote, user-assisted attacker to conduct a CSRF token fixation attack. This issue is triggered as previous CSRF tokens are not properly invalidated when a new token is created. If an attacker has knowledge of said token, a specially crafted request can be made to it, allowing the attacker to conduct CSRF attacks.

CVSS Scores

version 3.1