oss-sec mailing list archives

CVE request for 'devise' ruby gem


From: Reed Loden <reed () reedloden com>
Date: Mon, 28 Jan 2013 16:38:32 -0800

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Devise is a flexible authentication solution for Rails.

Security announcement made earlier today:

http://blog.plataformatec.com.br/2013/01/security-announcement-devise-v2-2-3-v2-1-3-v2-0-5-and-v1-5-3-released/

""""
Using a specially crafted request, an attacker could trick the database
type conversion code to return incorrect records. For some token values
this could allow an attacker to bypass the proper checks and gain
control of other accounts.
""""

I don't see a CVE yet for this issue, so could one be assigned, please?

Thanks,
~reed
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)

iEYEARECAAYFAlEHGggACgkQa6IiJvPDPVrpdwCfRZ74c++qybHRAY59U+U6a/VA
ok4An1pPVTZP4tRprJ+3HdWX1KDQUCUv
=LJdT
-----END PGP SIGNATURE-----

Current thread: