CVE-2013-0233

EUVD-2017-0267
Devise gem 2.2.x before 2.2.3, 2.1.x before 2.1.3, 2.0.x before 2.0.5, and 1.5.x before 1.5.4 for Ruby, when using certain databases, does not properly perform type conversion when performing database queries, which might allow remote attackers to cause incorrect results to be returned and bypass security checks via unknown vectors, as demonstrated by resetting passwords of arbitrary accounts.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 98%
Affected Products (NVD)
VendorProductVersion
plataformatecdevise
1.5.0
plataformatecdevise
1.5.1
plataformatecdevise
1.5.2
plataformatecdevise
1.5.3
plataformatecdevise
2.0.0
plataformatecdevise
2.0.1
plataformatecdevise
2.0.2
plataformatecdevise
2.0.3
plataformatecdevise
2.0.4
plataformatecdevise
2.1.0
plataformatecdevise
2.1.1
plataformatecdevise
2.1.2
plataformatecdevise
2.2.0
plataformatecdevise
2.2.1
plataformatecdevise
2.2.2
opensuseopensuse
12.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
ruby-devise
bookworm
4.8.1-1
fixed
bullseye
4.7.3-2
fixed
sid
4.9.3-1
fixed
trixie
4.9.3-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
ruby-devise
bionic
not-affected
focal
not-affected
groovy
not-affected
trusty
dne
xenial
not-affected
Common Weakness Enumeration