Bugzilla – Bug 1218017
VUL-0: CVE-2015-8314: rubygem-devise: mishandles Remember Me cookies for sessions
Last modified: 2023-12-13 14:00:03 UTC
The Devise gem before 3.5.4 for Ruby mishandles Remember Me cookies for sessions, which may allow an adversary to obtain unauthorized persistent application access. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-8314
openSUSE:Backports:SLE-15-SP4 rubygem-devise 4.4.1 openSUSE:Backports:SLE-15-SP5 rubygem-devise 4.4.1 openSUSE:Backports:SLE-15-SP6 rubygem-devise 4.4.1 openSUSE:Factory rubygem-devise 4.9.3 We have a higher version than affected. Closing as fixed.