CVE-2013-0233 – devise
Package
Manager: gem
Name: devise
Vulnerable Version: >=2.2.0 <2.2.3 || >=2.1.0 <2.1.3 || >=2.0.0 <2.0.5 || >=1.5.0 <1.5.4
Severity
Level: Medium
CVSS v3.1: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
EPSS: 0.67768 pctl0.98529
Details
Devise does not properly perform type conversion when performing database queries Devise gem 2.2.x before 2.2.3, 2.1.x before 2.1.3, 2.0.x before 2.0.5, and 1.5.x before 1.5.4 for Ruby, when using certain databases, does not properly perform type conversion when performing database queries, which might allow remote attackers to cause incorrect results to be returned and bypass security checks via unknown vectors, as demonstrated by resetting passwords of arbitrary accounts.
Metadata
Created: 2017-10-24T18:33:37Z
Modified: 2023-01-23T21:20:12Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2017/10/GHSA-jxhw-mg8m-2pj8/GHSA-jxhw-mg8m-2pj8.json
CWE IDs: ["CWE-704"]
Alternative ID: GHSA-jxhw-mg8m-2pj8
Finding: F113
Auto approve: 1