Vulnerabilities (CVE)

Filtered by vendor Heartcombo Subscribe
Filtered by product Devise
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2015-8314 1 Heartcombo 1 Devise 2024-11-21 N/A 7.5 HIGH
The Devise gem before 3.5.4 for Ruby mishandles Remember Me cookies for sessions, which may allow an adversary to obtain unauthorized persistent application access.