|
|
| |
|
| |
rubygem-devise: unauthorized account access
| Package(s): | rubygem-devise |
CVE #(s): | CVE-2013-0233
|
| Created: | March 4, 2013 |
Updated: | March 6, 2013 |
| Description: |
From the Novell bugzilla:
Using a specially crafted request, an attacker could trick the database
type conversion code to return incorrect records. For some token values
this could allow an attacker to bypass the proper checks and gain
control of other accounts. |
| Alerts: |
|
( Log in to post comments)
|
|
|