An issue was discovered in Plataformatec Devise before 4.7.1. It confirms accounts upon receiving a request with a blank confirmation_token, if a database record has a blank value in the confirmation_token column. (However, there is no scenario within Devise itself in which such database records would exist.)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NPlataformatec Devise
APPPlataformatec< 4.7.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Related vulnerabilities
CVE-2019-5421CRITICAL9.8PL ✓same product
Plataformatec Devise – race condition w module lockable umożliwia brute force
CVE-2013-0233MEDIUM6.8same product
Devise gem 2.2.x before 2.2.3, 2.1.x before 2.1.3, 2.0.x before 2.0.5, and 1.5.x before 1.5.4 for Ruby, when u...
CVE-2019-16676CRITICAL9.8PL ✓same vendor
Nieprawidłowa kontrola dostępu w Plataformatec Simple Form (RCE)