Filtered by vendor Devise Masquerade Project
Subscribe
Total
1 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2021-28680 | 1 Devise Masquerade Project | 1 Devise Masquerade | 2024-11-21 | 6.8 MEDIUM | 8.1 HIGH |
|
The devise_masquerade gem before 1.3 allows certain attacks when a password's salt is unknown. An application that uses this gem to let administrators masquerade/impersonate users loses one layer of security protection compared to a situation where Devise (without this extension) is used. If the server-side secret_key_base value became publicly known (for instance if it is committed to a public repository by mistake), there are still other protections in place that prevent an attacker from imper ...
Show More |
|||||