Security controls bypass or absence In ruby-devise
Description
The Devise gem before 3.5.4 for Ruby mishandles Remember Me cookies for sessions, which may allow an adversary to obtain unauthorized persistent application access.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
debian 12 | 3.5.6-2 | ||
debian 11 | 3.5.6-2 | ||
rubygems | 3.5.4 |
Aliases
1. 2. 3. 4. 5. 6. 7.
References
1. 2. 3. 4.