VDB
Sign up
MEDIUM

GHSA-jxhw-mg8m-2pj8

Devise does not properly perform type conversion when performing database queries

Quick fix

GHSA-jxhw-mg8m-2pj8 — devise: upgrade to the fixed version with the command below.

bundle update devise

Details

Devise gem 2.2.x before 2.2.3, 2.1.x before 2.1.3, 2.0.x before 2.0.5, and 1.5.x before 1.5.4 for Ruby, when using certain databases, does not properly perform type conversion when performing database queries, which might allow remote attackers to cause incorrect results to be returned and bypass security checks via unknown vectors, as demonstrated by resetting passwords of arbitrary accounts.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/devise
Introduced in: 2.2.0Fixed in: 2.2.3
Fixbundle update devise
RubyGems/devise
Introduced in: 2.1.0Fixed in: 2.1.3
Fixbundle update devise
RubyGems/devise
Introduced in: 2.0.0Fixed in: 2.0.5
Fixbundle update devise
RubyGems/devise
Introduced in: 1.5.0Fixed in: 1.5.4
Fixbundle update devise

References