CVE-2015-8314

7.5HIGH

The Devise gem before 3.5.4 for Ruby mishandles Remember Me cookies for sessions, which may allow an adversary to obtain unauthorized persistent application access.

Veröffentlicht: 12/12/2023Aktualisiert: 5/27/2025

Beschreibung

The Devise gem before 3.5.4 for Ruby mishandles Remember Me cookies for sessions, which may allow an adversary to obtain unauthorized persistent application access.

KI-AnalyseKI-gestützt

Betroffene Produkte

heartcombodevise

Referenzen