As a result of an incomplete fix for CVE-2015-7225, in versions of devise-two-factor prior to 4.0.2 it is possible to reuse a One-Time-Password (OTP) for one (and only one) immediately trailing interval. CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N)
Name | Vendor | Start Version | End Version |
---|---|---|---|
Devise-two-factor | Tinfoilsecurity | * | 4.0.2 (excluding) |
Ruby-devise-two-factor | Ubuntu | esm-apps/focal | * |
Ruby-devise-two-factor | Ubuntu | esm-apps/jammy | * |
Ruby-devise-two-factor | Ubuntu | esm-apps/xenial | * |
Ruby-devise-two-factor | Ubuntu | focal | * |
Ruby-devise-two-factor | Ubuntu | impish | * |
Ruby-devise-two-factor | Ubuntu | jammy | * |
Ruby-devise-two-factor | Ubuntu | kinetic | * |
Ruby-devise-two-factor | Ubuntu | upstream | * |
Ruby-devise-two-factor | Ubuntu | xenial | * |