VDB
Sign up
HIGH7.5

GHSA-746g-3gfp-hfhw

Devise Gem for Ruby Unauthorized Access Using "Remember Me" Cookie

Quick fix

GHSA-746g-3gfp-hfhw — devise: upgrade to the fixed version with the command below.

bundle update devise

Details

Devise version before 3.5.4 uses cookies to implement a "Remember me" functionality. However, it generates the same cookie for all devices. If an attacker manages to steal a remember me cookie and the user does not change the password frequently, the cookie can be used to gain access to the application indefinitely.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/devise
Introduced in: 0Fixed in: 3.5.4
Fixbundle update devise

References