CVE-2015-8314

7.5HIGH

The Devise gem before 3.5.4 for Ruby mishandles Remember Me cookies for sessions, which may allow an adversary to obtain unauthorized persistent application access.

发布于: 12/12/2023更新于: 5/27/2025

描述

The Devise gem before 3.5.4 for Ruby mishandles Remember Me cookies for sessions, which may allow an adversary to obtain unauthorized persistent application access.

AI分析AI驱动

受影响产品

heartcombodevise

参考资料