Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2013-0233


Devise gem 2.2.x before 2.2.3, 2.1.x before 2.1.3, 2.0.x before 2.0.5, and 1.5.x before 1.5.4 for Ruby, when using certain databases, does not properly perform type conversion when performing database queries, which might allow remote attackers to cause incorrect results to be returned and bypass security checks via unknown vectors, as demonstrated by resetting passwords of arbitrary accounts.


Published

2013-04-25T23:55:01.460

Last Modified

2025-04-11T00:51:21.963

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 6.8 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

8.6

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-399

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application plataformatec devise 1.5.0 Yes
Application plataformatec devise 1.5.1 Yes
Application plataformatec devise 1.5.2 Yes
Application plataformatec devise 1.5.3 Yes
Application plataformatec devise 2.0.0 Yes
Application plataformatec devise 2.0.1 Yes
Application plataformatec devise 2.0.2 Yes
Application plataformatec devise 2.0.3 Yes
Application plataformatec devise 2.0.4 Yes
Application plataformatec devise 2.1.0 Yes
Application plataformatec devise 2.1.1 Yes
Application plataformatec devise 2.1.2 Yes
Application plataformatec devise 2.2.0 Yes
Application plataformatec devise 2.2.1 Yes
Application plataformatec devise 2.2.2 Yes
Application ruby-lang ruby * No
Operating System opensuse opensuse 12.2 Yes

References