Date: Mon, 28 Jan 2013 16:38:32 -0800 From: Reed Loden <reed@...dloden.com> To: <oss-security@...ts.openwall.com> Subject: CVE request for 'devise' ruby gem -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Devise is a flexible authentication solution for Rails. Security announcement made earlier today: http://blog.plataformatec.com.br/2013/01/security-announcement-devise-v2-2-3-v2-1-3-v2-0-5-and-v1-5-3-released/ """" Using a specially crafted request, an attacker could trick the database type conversion code to return incorrect records. For some token values this could allow an attacker to bypass the proper checks and gain control of other accounts. """" I don't see a CVE yet for this issue, so could one be assigned, please? Thanks, ~reed -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.11 (GNU/Linux) iEYEARECAAYFAlEHGggACgkQa6IiJvPDPVrpdwCfRZ74c++qybHRAY59U+U6a/VA ok4An1pPVTZP4tRprJ+3HdWX1KDQUCUv =LJdT -----END PGP SIGNATURE-----
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.