CVE-2019-16109

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
08/09/2019
Last modified:
24/08/2020

Description

An issue was discovered in Plataformatec Devise before 4.7.1. It confirms accounts upon receiving a request with a blank confirmation_token, if a database record has a blank value in the confirmation_token column. (However, there is no scenario within Devise itself in which such database records would exist.)

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:plataformatec:devise:*:*:*:*:*:*:*:* 4.7.1 (excluding)