Ruby/devise/4.6.0
Flexible authentication solution for Rails with Warden
https://rubygems.org/gems/devise
MIT
2 Security Vulnerabilities
Authentication Bypass in Devise
- https://nvd.nist.gov/vuln/detail/CVE-2019-16109
- https://github.com/advisories/GHSA-fcjw-8rhj-gwwc
- https://github.com/plataformatec/devise/compare/v4.7.0...v4.7.1
- https://github.com/plataformatec/devise/issues/5071
- https://github.com/plataformatec/devise/pull/5132
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/devise/CVE-2019-16109.yml
An issue was discovered in Plataformatec Devise before 4.7.1. It confirms accounts upon receiving a request with a blank confirmationtoken, if a database record has a blank value in the confirmationtoken column. (However, there is no scenario within Devise itself in which such database records would exist.)
Devise Gem for Ruby confirmation token validation with a blank string
Devise before 4.7.1 confirms accounts upon receiving a request with a blank confirmationtoken, if a database record has a blank value in the confirmationtoken column. However, there is no scenario within Devise itself in which such database records would exist.
167 Other Versions
Version | License | Security | Released | |
---|---|---|---|---|
0.5.5 | UNKNOWN | 8 | 2009-11-19 - 22:55 | over 15 years |
0.5.4 | UNKNOWN | 8 | 2009-11-19 - 15:14 | over 15 years |
0.5.3 | UNKNOWN | 8 | 2009-11-18 - 11:48 | over 15 years |
0.5.2 | UNKNOWN | 8 | 2009-11-17 - 19:39 | over 15 years |
0.5.1 | UNKNOWN | 8 | 2009-11-15 - 20:15 | over 15 years |
0.5.0 | UNKNOWN | 8 | 2009-11-14 - 02:01 | over 15 years |
0.4.3 | UNKNOWN | 8 | 2009-11-10 - 03:01 | over 15 years |
0.4.2 | UNKNOWN | 8 | 2009-11-06 - 20:01 | over 15 years |
0.4.1 | UNKNOWN | 8 | 2009-11-04 - 03:34 | over 15 years |
0.4.0 | UNKNOWN | 8 | 2009-11-03 - 16:29 | over 15 years |
0.3.0 | UNKNOWN | 8 | 2009-10-30 - 13:43 | over 15 years |
0.2.3 | UNKNOWN | 8 | 2009-10-29 - 18:10 | over 15 years |
0.2.2 | UNKNOWN | 8 | 2009-10-28 - 13:33 | over 15 years |
0.2.1 | UNKNOWN | 8 | 2009-10-28 - 03:12 | over 15 years |
0.2.0 | UNKNOWN | 8 | 2009-10-25 - 01:45 | over 15 years |
0.1.1 | UNKNOWN | 8 | 2009-10-21 - 20:07 | over 15 years |
0.1.0 | UNKNOWN | 8 | 2009-10-21 - 05:34 | over 15 years |