RubySec

Providing security resources for the Ruby community

OSVDB-114435 (devise): CSRF token fixation attacks in Devise

CSRF token fixation attacks in Devise

Published: August 02, 2013

SECURITY IDENTIFIERS

GEM

devise

PATCHED VERSIONS

~> 2.2.5 >= 3.0.1

DESCRIPTION

Devise contains a flaw that allows a remote, user-assisted attacker to conduct a CSRF token fixation attack. This issue is triggered as previous CSRF tokens are not properly invalidated when a new token is created. If an attacker has knowledge of said token, a specially crafted request can be made to it, allowing the attacker to conduct CSRF attacks.

RELATED