Podatność CVE-2015-8314


Publikacja: 2023-12-12   Modyfikacja: 2023-12-14

Opis:
The Devise gem before 3.5.4 for Ruby mishandles Remember Me cookies for sessions, which may allow an adversary to obtain unauthorized persistent application access.

Typ:

CWE-312

(Cleartext Storage of Sensitive Information)

Affected software
Heartcombo -> Devise 

 Referencje:
https://rubysec.com/advisories/CVE-2015-8314/
https://github.com/advisories/GHSA-746g-3gfp-hfhw
https://github.com/heartcombo/devise/commit/c92996646aba2d25b2c3e235fe0c4f1a84b70d24

Copyright 2024, cxsecurity.com

 

Back to Top