Skip to content

devise-two-factor Security Advisory

Moderate
bsedat published GHSA-jm35-h8q2-73mp Apr 7, 2022

Package

bundler devise-two-factor (RubyGems)

Affected versions

< 4.0.2

Patched versions

4.0.2

Description

Impact

As a result of an incomplete fix for CVE-2015-7225, in versions of devise-two-factor prior to 4.0.2 it is possible to reuse a One-Time-Password (OTP) for one (and only one) immediately trailing interval.

Patches

This vulnerability has been patched in version 4.0.2 which was released on March 24th, 2022. Individuals using this package are strongly encouraged to upgrade as soon as possible.

Credit for discovery

Benoit Côté-Jodoin
Michael Nipper - #106

Severity

Moderate

CVE ID

CVE-2021-43177

Weaknesses

No CWEs