Devise gem 2.2.x before 2.2.3, 2.1.x before 2.1.3, 2.0.x before 2.0.5, and 1.5.x before 1.5.4 for Ruby, when using certain databases, does not properly perform type conversion when performing database queries, which might allow remote attackers to cause incorrect results to be returned and bypass security checks via unknown vectors, as demonstrated by resetting passwords of arbitrary accounts.
oryginał ENCVSS Vector
AV:N/AC:M/Au:N/C:P/I:P/A:POpensuse
OSOpensuse12.2Plataformatec Devise
APPPlataformatec1.5.01.5.11.5.21.5.32.0.02.0.12.0.22.0.32.0.42.1.02.1.12.1.22.2.02.2.12.2.2Ruby Lang Ruby
APPRuby-Langwszystkie wersje
🟢
PATCH DOSTĘPNY
Aktualizacja od producenta gotowa. Wdrożenie w ramach standardowego cyklu.
CWE
Referencje
Powiązane podatności
CVE-2016-4171CRITICAL9.8⚠ KEVPL ✓ten sam produkt
RCE w Adobe Flash Player 21.0.0.242 i wcześniejszych — aktywnie exploitowany
CVE-2016-4117CRITICAL9.8⚠ KEVPL ✓ten sam produkt
Adobe Flash Player — RCE umożliwiający wykonanie dowolnego kodu
CVE-2016-3427CRITICAL9.8⚠ KEVPL ✓ten sam produkt
Krytyczna podatność RCE w Oracle Java SE i JRockit — komponent JMX
CVE-2015-2590CRITICAL9.8⚠ KEVPL ✓ten sam produkt
Krytyczna podatność RCE w Oracle Java SE — komponent Libraries
CVE-2015-5119CRITICAL9.8⚠ KEVPL ✓ten sam produkt
Adobe Flash Player — use-after-free w klasie ByteArray umożliwia RCE