GHSA-73rf-6mrf-759q
Dashboard / Vulnerabilities / GHSA-73rf-6mrf-759q
Summary: devise Time-of-check Time-of-use Race Condition vulnerability
Details: Devise ruby gem before 4.6.0 when the `lockable` module is used is vulnerable to a time-of-check time-of-use (TOCTOU) race condition due to `increment_failed_attempts` within the `Devise::Models::Lockable` class not being concurrency safe.
References: https://nvd.nist.gov/vuln/detail/CVE-2019-5421, https://github.com/plataformatec/devise/issues/4981, https://github.com/plataformatec/devise/pull/4996, https://github.com/plataformatec/devise
Affected packages
Package
Name: devise
Purl: pkg:gem/devise
Affected ranges
Type: ECOSYSTEM
Events:
Introduced- 0
Fixed -4.6.0
Affected versions
0.1.0
0.1.1
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
