LWN.net Logo

rubygem-devise: unauthorized account access

Package(s):rubygem-devise CVE #(s):CVE-2013-0233
Created:March 4, 2013 Updated:March 6, 2013
Description: From the Novell bugzilla:

Using a specially crafted request, an attacker could trick the database type conversion code to return incorrect records. For some token values this could allow an attacker to bypass the proper checks and gain control of other accounts.

Alerts:
openSUSE openSUSE-SU-2013:0374-1 2013-03-01

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds