CVE-2013-0233
Summary
| CVE | CVE-2013-0233 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2013-04-25 23:55:01 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Devise gem 2.2.x before 2.2.3, 2.1.x before 2.1.3, 2.0.x before 2.0.5, and 1.5.x before 1.5.4 for Ruby, when using certain databases, does not properly perform type conversion when performing database queries, which might allow remote attackers to cause incorrect results to be returned and bypass security checks via unknown vectors, as demonstrated by resetting passwords of arbitrary accounts. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:M/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Opensuse | Opensuse | 12.2 | All | All | All |
| Application | Plataformatec | Devise | 1.5.0 | All | All | All |
| Application | Plataformatec | Devise | 1.5.1 | All | All | All |
| Application | Plataformatec | Devise | 1.5.2 | All | All | All |
| Application | Plataformatec | Devise | 1.5.3 | All | All | All |
| Application | Plataformatec | Devise | 2.0.0 | All | All | All |
| Application | Plataformatec | Devise | 2.0.1 | All | All | All |
| Application | Plataformatec | Devise | 2.0.2 | All | All | All |
| Application | Plataformatec | Devise | 2.0.3 | All | All | All |
| Application | Plataformatec | Devise | 2.0.4 | All | All | All |
| Application | Plataformatec | Devise | 2.1.0 | All | All | All |
| Application | Plataformatec | Devise | 2.1.1 | All | All | All |
| Application | Plataformatec | Devise | 2.1.2 | All | All | All |
| Application | Plataformatec | Devise | 2.2.0 | All | All | All |
| Application | Plataformatec | Devise | 2.2.1 | All | All | All |
| Application | Plataformatec | Devise | 2.2.2 | All | All | All |
| Application | Ruby-lang | Ruby | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| openSUSE-SU-2013:0374-1: moderate: rubygem-devise: updated to version 1. | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Security announcement: Devise v2.2.3, v2.1.3, v2.0.5 and v1.5.4 released | Plataformatec Blog | af854a3a-2127-422b-91ae-364da2661108 | blog.plataformatec.com.br | Vendor Advisory |
| Ruby on Rails Devise Authentication Password Reset | Metasploit Exploit Database (DB) | af854a3a-2127-422b-91ae-364da2661108 | www.metasploit.com | Exploit |
| Update Gemfile for recent Devise security vulnerability (CVE-2013-0233) · Issue #261 · Snorby/snorby · GitHub | af854a3a-2127-422b-91ae-364da2661108 | github.com | |
| MySQL madness and Rails | Lands of Packets | af854a3a-2127-422b-91ae-364da2661108 | www.phenoelit.org | Exploit |
| oss-security - Re: CVE request for 'devise' ruby gem | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| Devise CVE-2013-0233 Security Bypass Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.