logo

CVE-2013-0233 devise

Package

Manager: gem
Name: devise
Vulnerable Version: >=2.2.0 <2.2.3 || >=2.1.0 <2.1.3 || >=2.0.0 <2.0.5 || >=1.5.0 <1.5.4

Severity

Level: Medium

CVSS v3.1: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C

CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

EPSS: 0.67768 pctl0.98529

Details

Devise does not properly perform type conversion when performing database queries Devise gem 2.2.x before 2.2.3, 2.1.x before 2.1.3, 2.0.x before 2.0.5, and 1.5.x before 1.5.4 for Ruby, when using certain databases, does not properly perform type conversion when performing database queries, which might allow remote attackers to cause incorrect results to be returned and bypass security checks via unknown vectors, as demonstrated by resetting passwords of arbitrary accounts.

Metadata

Created: 2017-10-24T18:33:37Z
Modified: 2023-01-23T21:20:12Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2017/10/GHSA-jxhw-mg8m-2pj8/GHSA-jxhw-mg8m-2pj8.json
CWE IDs: ["CWE-704"]
Alternative ID: GHSA-jxhw-mg8m-2pj8
Finding: F113
Auto approve: 1