As a result of an incomplete fix for CVE-2015-7225, in versions of devise-two-factor prior to 4.0.2 it is possible to reuse a One-Time-Password (OTP) for one (and only one) immediately trailing interval. CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N)
Advisories
Source ID Title
EUVD EUVD EUVD-2022-1774 As a result of an incomplete fix for CVE-2015-7225, in versions of devise-two-factor prior to 4.0.2 it is possible to reuse a One-Time-Password (OTP) for one (and only one) immediately trailing interval. CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N)
Github GHSA Github GHSA GHSA-jm35-h8q2-73mp Improper one time password handling in devise-two-factor
Ubuntu USN Ubuntu USN USN-7050-1 Devise-Two-Factor vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: SNPS

Published:

Updated: 2024-08-04T03:47:13.623Z

Reserved: 2021-11-01T00:00:00

Link: CVE-2021-43177

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-04-11T20:15:16.037

Modified: 2024-11-21T06:28:46.630

Link: CVE-2021-43177

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.