CVE-2013-0233

Severity CVSS v4.0:
Pending analysis
Type:
CWE-399 Resource Management Errors
Publication date:
25/04/2013
Last modified:
11/04/2025

Description

Devise gem 2.2.x before 2.2.3, 2.1.x before 2.1.3, 2.0.x before 2.0.5, and 1.5.x before 1.5.4 for Ruby, when using certain databases, does not properly perform type conversion when performing database queries, which might allow remote attackers to cause incorrect results to be returned and bypass security checks via unknown vectors, as demonstrated by resetting passwords of arbitrary accounts.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:plataformatec:devise:1.5.0:*:*:*:*:*:*:*
cpe:2.3:a:plataformatec:devise:1.5.1:*:*:*:*:*:*:*
cpe:2.3:a:plataformatec:devise:1.5.2:*:*:*:*:*:*:*
cpe:2.3:a:plataformatec:devise:1.5.3:*:*:*:*:*:*:*
cpe:2.3:a:plataformatec:devise:2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:plataformatec:devise:2.0.1:*:*:*:*:*:*:*
cpe:2.3:a:plataformatec:devise:2.0.2:*:*:*:*:*:*:*
cpe:2.3:a:plataformatec:devise:2.0.3:*:*:*:*:*:*:*
cpe:2.3:a:plataformatec:devise:2.0.4:*:*:*:*:*:*:*
cpe:2.3:a:plataformatec:devise:2.1.0:*:*:*:*:*:*:*
cpe:2.3:a:plataformatec:devise:2.1.1:*:*:*:*:*:*:*
cpe:2.3:a:plataformatec:devise:2.1.2:*:*:*:*:*:*:*
cpe:2.3:a:plataformatec:devise:2.2.0:*:*:*:*:*:*:*
cpe:2.3:a:plataformatec:devise:2.2.1:*:*:*:*:*:*:*
cpe:2.3:a:plataformatec:devise:2.2.2:*:*:*:*:*:*:*