6.8

CVE-2013-0233

Exploit
Devise gem 2.2.x before 2.2.3, 2.1.x before 2.1.3, 2.0.x before 2.0.5, and 1.5.x before 1.5.4 for Ruby, when using certain databases, does not properly perform type conversion when performing database queries, which might allow remote attackers to cause incorrect results to be returned and bypass security checks via unknown vectors, as demonstrated by resetting passwords of arbitrary accounts.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Plataformatec ≫ Devise Version 1.5.0
   Ruby-lang ≫ Ruby
Plataformatec ≫ Devise Version 1.5.1
   Ruby-lang ≫ Ruby
Plataformatec ≫ Devise Version 1.5.2
   Ruby-lang ≫ Ruby
Plataformatec ≫ Devise Version 1.5.3
   Ruby-lang ≫ Ruby
Plataformatec ≫ Devise Version 2.0.0
   Ruby-lang ≫ Ruby
Plataformatec ≫ Devise Version 2.0.1
   Ruby-lang ≫ Ruby
Plataformatec ≫ Devise Version 2.0.2
   Ruby-lang ≫ Ruby
Plataformatec ≫ Devise Version 2.0.3
   Ruby-lang ≫ Ruby
Plataformatec ≫ Devise Version 2.0.4
   Ruby-lang ≫ Ruby
Plataformatec ≫ Devise Version 2.1.0
   Ruby-lang ≫ Ruby
Plataformatec ≫ Devise Version 2.1.1
   Ruby-lang ≫ Ruby
Plataformatec ≫ Devise Version 2.1.2
   Ruby-lang ≫ Ruby
Plataformatec ≫ Devise Version 2.2.0
   Ruby-lang ≫ Ruby
Plataformatec ≫ Devise Version 2.2.1
   Ruby-lang ≫ Ruby
Plataformatec ≫ Devise Version 2.2.2
   Ruby-lang ≫ Ruby
Opensuse ≫ Opensuse Version 12.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 14.13% 0.961
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://blog.plataformatec.com.br/2013/01/security-announcement-devise-v2-2-3-v2-1-3-v2-0-5-and-v1-5-3-released/
Vendor Advisory
http://lists.opensuse.org/opensuse-updates/2013-03/msg00000.html
http://www.metasploit.com/modules/auxiliary/admin/http/rails_devise_pass_reset
Exploit
http://www.openwall.com/lists/oss-security/2013/01/29/3
http://www.phenoelit.org/blog/archives/2013/02/05/mysql_madness_and_rails/index.html
Exploit
http://www.securityfocus.com/bid/57577
https://github.com/Snorby/snorby/issues/261