Launch Week Day 1: Announcing Security Design Review
HIGH 7.5 RubyGems

Devise Gem for Ruby Unauthorized Access Using "Remember Me" Cookie

GHSA-746g-3gfp-hfhw · CVE-2015-8314

Published · Modified

Description

Devise version before 3.5.4 uses cookies to implement a "Remember me" functionality. However, it generates the same cookie for all devices. If an attacker manages to steal a remember me cookie and the user does not change the password frequently, the cookie can be used to gain access to the application indefinitely.

Ready to move

Start Securing

Free, no credit card | First findings in minutes