CVE-2013-0233

Devise gem 2.2.x before 2.2.3, 2.1.x before 2.1.3, 2.0.x before 2.0.5, and 1.5.x before 1.5.4 for Ruby, when using certain databases, does not properly perform type conversion when performing database queries, which might allow remote attackers to cause incorrect results to be returned and bypass security checks via unknown vectors, as demonstrated by resetting passwords of arbitrary accounts.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 98%
VendorProductVersion
plataformatecdevise
1.5.0
plataformatecdevise
1.5.1
plataformatecdevise
1.5.2
plataformatecdevise
1.5.3
plataformatecdevise
2.0.0
plataformatecdevise
2.0.1
plataformatecdevise
2.0.2
plataformatecdevise
2.0.3
plataformatecdevise
2.0.4
plataformatecdevise
2.1.0
plataformatecdevise
2.1.1
plataformatecdevise
2.1.2
plataformatecdevise
2.2.0
plataformatecdevise
2.2.1
plataformatecdevise
2.2.2
opensuseopensuse
12.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
ruby-devise
bullseye
4.7.3-2
fixed
bookworm
4.8.1-1
fixed
sid
4.9.3-1
fixed
trixie
4.9.3-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
ruby-devise
groovy
not-affected
focal
not-affected
bionic
not-affected
xenial
not-affected
trusty
dne
Common Weakness Enumeration