CVE-2021-43177: Medium severity tinfoilsecurity devise two factor vulnerability
Published Apr 11, 2022
·Updated
As a result of an incomplete fix for CVE-2015-7225, in versions of devise-two-factor prior to 4.0.2 it is possible to reuse a One-Time-Password (OTP) for one (and only one) immediately trailing interval. CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N)
Affected Software
2 affected componentsFixes available
debian/ruby-devise-two-factor<=3.1.0-2
4.0.2-1
Tinfoilsecurity Devise-two-factor<4.0.2
Event History
Apr 11, 2022
CVE Published
via MITRE·07:37 PM
Data Sourced
via MITRE·07:37 PM
DescriptionWeakness
Oct 1, 2024
Data Sourced
via Launchpad·05:11 PM
Description
Oct 9, 2024
Data Sourced
via Ubuntu·05:12 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-43177?
CVE-2021-43177 has a CVSS score indicating a medium severity level.
2
How do I fix CVE-2021-43177?
To fix CVE-2021-43177, update to devise-two-factor version 4.0.2 or later.
3
What versions are affected by CVE-2021-43177?
CVE-2021-43177 affects all versions of devise-two-factor prior to 4.0.2.
4
What is the nature of the vulnerability in CVE-2021-43177?
CVE-2021-43177 allows for the reuse of a One-Time-Password (OTP) for one subsequent interval due to an incomplete fix.
5
Who is impacted by CVE-2021-43177?
Developers using the devise-two-factor library prior to version 4.0.2 are impacted by CVE-2021-43177.