oss-sec mailing list archives
CVE request for 'devise' ruby gem
From: Reed Loden <reed () reedloden com>
Date: Mon, 28 Jan 2013 16:38:32 -0800
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Devise is a flexible authentication solution for Rails. Security announcement made earlier today: http://blog.plataformatec.com.br/2013/01/security-announcement-devise-v2-2-3-v2-1-3-v2-0-5-and-v1-5-3-released/ """" Using a specially crafted request, an attacker could trick the database type conversion code to return incorrect records. For some token values this could allow an attacker to bypass the proper checks and gain control of other accounts. """" I don't see a CVE yet for this issue, so could one be assigned, please? Thanks, ~reed -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.11 (GNU/Linux) iEYEARECAAYFAlEHGggACgkQa6IiJvPDPVrpdwCfRZ74c++qybHRAY59U+U6a/VA ok4An1pPVTZP4tRprJ+3HdWX1KDQUCUv =LJdT -----END PGP SIGNATURE-----
Current thread:
- CVE request for 'devise' ruby gem Reed Loden (Jan 28)
- Re: CVE request for 'devise' ruby gem Kurt Seifried (Jan 28)