UNKNOWN RubyGems
devise Time-of-check Time-of-use Race Condition vulnerability
GHSA-73rf-6mrf-759q · CVE-2019-5421
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Devise ruby gem before 4.6.0 when the lockable module is used is vulnerable to a time-of-check time-of-use (TOCTOU) race condition due to increment_failed_attempts within the Devise::Models::Lockable class not being concurrency safe.
Ready to move
Start Securing
Free, no credit card | First findings in minutes