HIGH7.5
GHSA-746g-3gfp-hfhw
Devise Gem for Ruby Unauthorized Access Using "Remember Me" Cookie
Quick fix
GHSA-746g-3gfp-hfhw — devise: upgrade to the fixed version with the command below.
bundle update deviseDetails
Devise version before 3.5.4 uses cookies to implement a "Remember me" functionality. However, it generates the same cookie for all devices. If an attacker manages to steal a remember me cookie and the user does not change the password frequently, the cookie can be used to gain access to the application indefinitely.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2015-8314[ADVISORY]
- https://github.com/heartcombo/devise/commit/c92996646aba2d25b2c3e235fe0c4f1a84b70d24[WEB]
- https://github.com/advisories/GHSA-746g-3gfp-hfhw[ADVISORY]
- https://github.com/heartcombo/devise[PACKAGE]
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/devise/CVE-2015-8314.yml[WEB]
- https://rubysec.com/advisories/CVE-2015-8314[WEB]
- http://blog.plataformatec.com.br/2016/01/improve-remember-me-cookie-expiration-in-devise[WEB]