UBUNTU-CVE-2019-16109
Dashboard / Vulnerabilities / UBUNTU-CVE-2019-16109
Summary:
Details: An issue was discovered in Plataformatec Devise before 4.7.1. It confirms accounts upon receiving a request with a blank confirmation_token, if a database record has a blank value in the confirmation_token column. (However, there is no scenario within Devise itself in which such database records would exist.)
References: https://ubuntu.com/security/CVE-2019-16109, https://github.com/plataformatec/devise/compare/v4.7.0...v4.7.1, https://github.com/plataformatec/devise/issues/5071, https://github.com/plataformatec/devise/pull/5132, https://www.cve.org/CVERecord?id=CVE-2019-16109
Affected packages
Package
Name: ruby-devise
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
