Description
The Devise gem before 3.5.4 for Ruby mishandles Remember Me cookies for sessions, which may allow an adversary to obtain unauthorized persistent application access.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-746g-3gfp-hfhw | Devise Gem for Ruby Unauthorized Access Using "Remember Me" Cookie |
References
History
Tue, 27 May 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-05-27T14:34:06.860Z
Reserved: 2015-11-22T00:00:00.000Z
Link: CVE-2015-8314
Updated: 2024-08-06T08:13:32.124Z
Status : Modified
Published: 2023-12-12T17:15:07.450
Modified: 2025-05-27T15:15:23.300
Link: CVE-2015-8314
No data.
OpenCVE Enrichment
No data.
Weaknesses
Github GHSA