Authentication Bypass in Devise
Moderate severity
GitHub Reviewed
Published
Sep 11, 2019
to the GitHub Advisory Database
•
Updated Nov 10, 2023
Description
Published by the National Vulnerability Database
Sep 8, 2019
Reviewed
Sep 11, 2019
Published to the GitHub Advisory Database
Sep 11, 2019
Last updated
Nov 10, 2023
An issue was discovered in Plataformatec Devise before 4.7.1. It confirms accounts upon receiving a request with a blank confirmation_token, if a database record has a blank value in the confirmation_token column. (However, there is no scenario within Devise itself in which such database records would exist.)
References