CVE-2019-16109: Medium severity devise vulnerability
An issue was discovered in Plataformatec Devise before 4.7.1. It confirms accounts upon receiving a request with a blank confirmationtoken, if a database record has a blank value in the confirmationtoken column. (However, there is no scenario within Devise itself in which such database records would exist.)
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2019-16109.
What is the severity of CVE-2019-16109?
The severity of CVE-2019-16109 is medium with a severity value of 5.3.
What is the affected software for CVE-2019-16109?
The affected software for CVE-2019-16109 is Plataformatec Devise up to version 4.7.1.
How can I fix CVE-2019-16109?
To fix CVE-2019-16109, upgrade to Plataformatec Devise version 4.7.1 or higher.
Where can I find more information about CVE-2019-16109?
You can find more information about CVE-2019-16109 in the following references: [Link1](https://github.com/plataformatec/devise/compare/v4.7.0...v4.7.1), [Link2](https://github.com/plataformatec/devise/issues/5071), [Link3](https://github.com/plataformatec/devise/pull/5132).