Session Cookie Vulnerability in Devise Gem by HeartCombo
CVE-2015-8314

7.5HIGH

Key Information:

Vendor

HeartCombo

Status
Vendor
CVE Published:
12 December 2023

What is CVE-2015-8314?

The Devise gem, a widely used authentication solution for Ruby applications, prior to version 3.5.4, contains a weakness in its handling of 'Remember Me' cookies. This flaw potentially allows attackers to breach persistent application sessions, granting them unauthorized access to user accounts. Developers utilizing affected versions should upgrade to ensure that their applications maintain proper session security and mitigate such risks.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.