Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Date: Mon, 28 Jan 2013 16:38:32 -0800
From: Reed Loden <reed@...dloden.com>
To: <oss-security@...ts.openwall.com>
Subject: CVE request for 'devise' ruby gem

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Devise is a flexible authentication solution for Rails.

Security announcement made earlier today:

http://blog.plataformatec.com.br/2013/01/security-announcement-devise-v2-2-3-v2-1-3-v2-0-5-and-v1-5-3-released/

""""
Using a specially crafted request, an attacker could trick the database
type conversion code to return incorrect records. For some token values
this could allow an attacker to bypass the proper checks and gain
control of other accounts.
""""

I don't see a CVE yet for this issue, so could one be assigned, please?

Thanks,
~reed
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)

iEYEARECAAYFAlEHGggACgkQa6IiJvPDPVrpdwCfRZ74c++qybHRAY59U+U6a/VA
ok4An1pPVTZP4tRprJ+3HdWX1KDQUCUv
=LJdT
-----END PGP SIGNATURE-----

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.