Vulnerabilities (CVE)

Filtered by vendor Devise Masquerade Project
Filtered by product Devise Masquerade
Angry Yack Logo
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-28680 1 Devise Masquerade Project 1 Devise Masquerade 2024-11-21 6.8 MEDIUM 8.1 HIGH
The devise_masquerade gem before 1.3 allows certain attacks when a password's salt is unknown. An application that uses this gem to let administrators masquerade/impersonate users loses one layer of security protection compared to a situation where Devise (without this extension) is used. If the server-side secret_key_base value became publicly known (for instance if it is committed to a public repository by mistake), there are still other protections in place that prevent an attacker from imper ...

Show More