In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade devise_security_extension
to version 0.10.0 or higher.
devise_security_extension
is an enterprise security extension for devise.
Affected versions of the package are vulnerable to Authentication Bypass. Any user updating their password will elevate their privileges to admin by the password updating method.