QID 996700

Date Published: 2024-01-15

QID 996700: Rubygems (Rubygems) Security Update for devise-two-factor (GHSA-chcr-x7hc-8fp8)

Devise-Two-Factor does not throttle or otherwise restrict login attempts at the server by default. When combined with the Time-based One Time Password algorithm's (TOTP) inherent entropy limitations, it's possible for an attacker to bypass the 2FA mechanism through brute-force attacks.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Critical - 8.1 severity.
  • CVSS V2 rated as Medium - 5.4 severity.
  • Solution
    Refer to Github security advisory GHSA-chcr-x7hc-8fp8 for updates and patch information.
    Vendor References

    CVEs related to QID 996700

    Software Advisories
    Advisory ID Software Component Link