MEDIUM · 6.8

CVE-2013-0233

Devise gem 2.2.x before 2.2.3, 2.1.x before 2.1.3, 2.0.x before 2.0.5, and 1.5.x before 1.5.4 for Ruby, when using certain databases, does not properly perform type conversion when performing database...

Vulnerability Description

Devise gem 2.2.x before 2.2.3, 2.1.x before 2.1.3, 2.0.x before 2.0.5, and 1.5.x before 1.5.4 for Ruby, when using certain databases, does not properly perform type conversion when performing database queries, which might allow remote attackers to cause incorrect results to be returned and bypass security checks via unknown vectors, as demonstrated by resetting passwords of arbitrary accounts.

CVSS Score

6.8

MEDIUM

AV:N/AC:M/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
PlataformatecDevise1.5.0
Ruby-LangRubyAll versions
OpensuseOpensuse12.2

Related Weaknesses (CWE)

References

FAQ

What is CVE-2013-0233?

CVE-2013-0233 is a vulnerability with a CVSS score of 6.8 (MEDIUM). Devise gem 2.2.x before 2.2.3, 2.1.x before 2.1.3, 2.0.x before 2.0.5, and 1.5.x before 1.5.4 for Ruby, when using certain databases, does not properly perform type conversion when performing database...

How severe is CVE-2013-0233?

CVE-2013-0233 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2013-0233?

Check the references section above for vendor advisories and patch information. Affected products include: Plataformatec Devise, Ruby-Lang Ruby, Opensuse Opensuse.