Launch Week Day 1: Announcing Security Design Review
UNKNOWN RubyGems

devise Time-of-check Time-of-use Race Condition vulnerability

GHSA-73rf-6mrf-759q · CVE-2019-5421

Published · Modified

Description

Devise ruby gem before 4.6.0 when the lockable module is used is vulnerable to a time-of-check time-of-use (TOCTOU) race condition due to increment_failed_attempts within the Devise::Models::Lockable class not being concurrency safe.

Ready to move

Start Securing

Free, no credit card | First findings in minutes