devise-two-factor
Barebones two-factor authentication with Devise
Activity
- Latest release
- 1w ago
- Total releases
- 28
- Cadence
- ~4 months
- Last 12 months
- 5
Reach
- Stars
- 1.3k
Details
- License
- MIT
- First release
- May 20, 2014
| Version | Released | |
|---|---|---|
6.4.1
patch
|
6.4.1
patch
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
6.4.0
minor
|
6.4.0
minor
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
6.3.1
patch
|
6.3.1
patch
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
6.3.0
minor
|
6.3.0
minor
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
6.2.0
minor
|
6.2.0
minor
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
6.1.0
minor
|
6.1.0
minor
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
6.0.0
major
|
6.0.0
major
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
5.1.0
minor
1 CVE
CVE-2024-8796
GHSA-qjxf-mc72-wjr2
Sep 17, 2024
Devise-Two-Factor Authentication Uses Insufficient Default OTP Shared Secret Length
Medium
Network
High
Low
None
SummaryUnder the default configuration, Devise-Two-Factor versions 1.0.0 or >= 4.0.0 & < 6.0.0 generate TOTP shared secrets that are 120 bits instead of the 128-bit minimum defined by RFC 4226. Using a shared secret shorter than the minimum to generate a multi-factor authentication code could make it easier for an attacker to guess the shared secret and generate valid TOTP codes. RemediationDevise-Two-Factor should be upgraded to version v6.0.0 as soon as possible. After upgrading, the length of shared secrets and TOTP URLs generated by the library will increase since the new shared secrets will be longer. If upgrading is not possible, you can override the default After upgrading or implementing the workaround, applications using Devise-Two-Factor may wish to migrate users to the new OTP length to provide increased protection for those accounts. Turning off OTP for users by setting BackgroundDevise-Two-Factor uses ROTP to generate shared secrets for TOTP. In ROTP < 5.0.0, the first argument to the Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
5.0.0
5.1.0
1.0.0
Fixed in
6.0.0
References Updated Sep 20, 2024 · Source: OSV.dev |
5.1.0
minor
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
4.1.1
patch
1 CVE
CVE-2024-8796
GHSA-qjxf-mc72-wjr2
Sep 17, 2024
Devise-Two-Factor Authentication Uses Insufficient Default OTP Shared Secret Length
Medium
Network
High
Low
None
SummaryUnder the default configuration, Devise-Two-Factor versions 1.0.0 or >= 4.0.0 & < 6.0.0 generate TOTP shared secrets that are 120 bits instead of the 128-bit minimum defined by RFC 4226. Using a shared secret shorter than the minimum to generate a multi-factor authentication code could make it easier for an attacker to guess the shared secret and generate valid TOTP codes. RemediationDevise-Two-Factor should be upgraded to version v6.0.0 as soon as possible. After upgrading, the length of shared secrets and TOTP URLs generated by the library will increase since the new shared secrets will be longer. If upgrading is not possible, you can override the default After upgrading or implementing the workaround, applications using Devise-Two-Factor may wish to migrate users to the new OTP length to provide increased protection for those accounts. Turning off OTP for users by setting BackgroundDevise-Two-Factor uses ROTP to generate shared secrets for TOTP. In ROTP < 5.0.0, the first argument to the Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
5.0.0
5.1.0
1.0.0
Fixed in
6.0.0
References Updated Sep 20, 2024 · Source: OSV.dev |
4.1.1
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
4.1.0
minor
1 CVE
CVE-2024-8796
GHSA-qjxf-mc72-wjr2
Sep 17, 2024
Devise-Two-Factor Authentication Uses Insufficient Default OTP Shared Secret Length
Medium
Network
High
Low
None
SummaryUnder the default configuration, Devise-Two-Factor versions 1.0.0 or >= 4.0.0 & < 6.0.0 generate TOTP shared secrets that are 120 bits instead of the 128-bit minimum defined by RFC 4226. Using a shared secret shorter than the minimum to generate a multi-factor authentication code could make it easier for an attacker to guess the shared secret and generate valid TOTP codes. RemediationDevise-Two-Factor should be upgraded to version v6.0.0 as soon as possible. After upgrading, the length of shared secrets and TOTP URLs generated by the library will increase since the new shared secrets will be longer. If upgrading is not possible, you can override the default After upgrading or implementing the workaround, applications using Devise-Two-Factor may wish to migrate users to the new OTP length to provide increased protection for those accounts. Turning off OTP for users by setting BackgroundDevise-Two-Factor uses ROTP to generate shared secrets for TOTP. In ROTP < 5.0.0, the first argument to the Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
5.0.0
5.1.0
1.0.0
Fixed in
6.0.0
References Updated Sep 20, 2024 · Source: OSV.dev |
4.1.0
minor
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
5.0.0
major
1 CVE
CVE-2024-8796
GHSA-qjxf-mc72-wjr2
Sep 17, 2024
Devise-Two-Factor Authentication Uses Insufficient Default OTP Shared Secret Length
Medium
Network
High
Low
None
SummaryUnder the default configuration, Devise-Two-Factor versions 1.0.0 or >= 4.0.0 & < 6.0.0 generate TOTP shared secrets that are 120 bits instead of the 128-bit minimum defined by RFC 4226. Using a shared secret shorter than the minimum to generate a multi-factor authentication code could make it easier for an attacker to guess the shared secret and generate valid TOTP codes. RemediationDevise-Two-Factor should be upgraded to version v6.0.0 as soon as possible. After upgrading, the length of shared secrets and TOTP URLs generated by the library will increase since the new shared secrets will be longer. If upgrading is not possible, you can override the default After upgrading or implementing the workaround, applications using Devise-Two-Factor may wish to migrate users to the new OTP length to provide increased protection for those accounts. Turning off OTP for users by setting BackgroundDevise-Two-Factor uses ROTP to generate shared secrets for TOTP. In ROTP < 5.0.0, the first argument to the Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
5.0.0
5.1.0
1.0.0
Fixed in
6.0.0
References Updated Sep 20, 2024 · Source: OSV.dev |
5.0.0
major
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
4.0.2
patch
1 CVE
CVE-2024-8796
GHSA-qjxf-mc72-wjr2
Sep 17, 2024
Devise-Two-Factor Authentication Uses Insufficient Default OTP Shared Secret Length
Medium
Network
High
Low
None
SummaryUnder the default configuration, Devise-Two-Factor versions 1.0.0 or >= 4.0.0 & < 6.0.0 generate TOTP shared secrets that are 120 bits instead of the 128-bit minimum defined by RFC 4226. Using a shared secret shorter than the minimum to generate a multi-factor authentication code could make it easier for an attacker to guess the shared secret and generate valid TOTP codes. RemediationDevise-Two-Factor should be upgraded to version v6.0.0 as soon as possible. After upgrading, the length of shared secrets and TOTP URLs generated by the library will increase since the new shared secrets will be longer. If upgrading is not possible, you can override the default After upgrading or implementing the workaround, applications using Devise-Two-Factor may wish to migrate users to the new OTP length to provide increased protection for those accounts. Turning off OTP for users by setting BackgroundDevise-Two-Factor uses ROTP to generate shared secrets for TOTP. In ROTP < 5.0.0, the first argument to the Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
5.0.0
5.1.0
1.0.0
Fixed in
6.0.0
References Updated Sep 20, 2024 · Source: OSV.dev |
4.0.2
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
4.0.1
patch
2 CVEs
CVE-2024-8796
GHSA-qjxf-mc72-wjr2
Sep 17, 2024
Devise-Two-Factor Authentication Uses Insufficient Default OTP Shared Secret Length
Medium
Network
High
Low
None
SummaryUnder the default configuration, Devise-Two-Factor versions 1.0.0 or >= 4.0.0 & < 6.0.0 generate TOTP shared secrets that are 120 bits instead of the 128-bit minimum defined by RFC 4226. Using a shared secret shorter than the minimum to generate a multi-factor authentication code could make it easier for an attacker to guess the shared secret and generate valid TOTP codes. RemediationDevise-Two-Factor should be upgraded to version v6.0.0 as soon as possible. After upgrading, the length of shared secrets and TOTP URLs generated by the library will increase since the new shared secrets will be longer. If upgrading is not possible, you can override the default After upgrading or implementing the workaround, applications using Devise-Two-Factor may wish to migrate users to the new OTP length to provide increased protection for those accounts. Turning off OTP for users by setting BackgroundDevise-Two-Factor uses ROTP to generate shared secrets for TOTP. In ROTP < 5.0.0, the first argument to the Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
5.0.0
5.1.0
1.0.0
Fixed in
6.0.0
References Updated Sep 20, 2024 · Source: OSV.dev
CVE-2021-43177
GHSA-jm35-h8q2-73mp
Apr 07, 2022
Improper one time password handling in devise-two-factor
5.3
/ 10
Medium
Network
High
Low
None
Unchanged
High
None
None
ImpactAs a result of an incomplete fix for CVE-2015-7225, in versions of devise-two-factor prior to 4.0.2 it is possible to reuse a One-Time-Password (OTP) for one (and only one) immediately trailing interval. PatchesThis vulnerability has been patched in version 4.0.2 which was released on March 24th, 2022. Individuals using this package are strongly encouraged to upgrade as soon as possible. Credit for discoveryBenoit Côté-Jodoin Michael Nipper - https://github.com/tinfoil/devise-two-factor/issues/106 Affected versions
1.0.0
1.0.1
1.0.2
1.1.0
2.0.0
2.0.1
2.1.0
2.2.0
2.2.1
3.0.0
3.0.1
3.0.2
+ 4 more Show less
3.0.3
3.1.0
4.0.0
4.0.1
Fixed in
4.0.2
References
Updated Aug 27, 2026 · Source: OSV.dev |
4.0.1
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
4.0.0
major
2 CVEs
CVE-2024-8796
GHSA-qjxf-mc72-wjr2
Sep 17, 2024
Devise-Two-Factor Authentication Uses Insufficient Default OTP Shared Secret Length
Medium
Network
High
Low
None
SummaryUnder the default configuration, Devise-Two-Factor versions 1.0.0 or >= 4.0.0 & < 6.0.0 generate TOTP shared secrets that are 120 bits instead of the 128-bit minimum defined by RFC 4226. Using a shared secret shorter than the minimum to generate a multi-factor authentication code could make it easier for an attacker to guess the shared secret and generate valid TOTP codes. RemediationDevise-Two-Factor should be upgraded to version v6.0.0 as soon as possible. After upgrading, the length of shared secrets and TOTP URLs generated by the library will increase since the new shared secrets will be longer. If upgrading is not possible, you can override the default After upgrading or implementing the workaround, applications using Devise-Two-Factor may wish to migrate users to the new OTP length to provide increased protection for those accounts. Turning off OTP for users by setting BackgroundDevise-Two-Factor uses ROTP to generate shared secrets for TOTP. In ROTP < 5.0.0, the first argument to the Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
5.0.0
5.1.0
1.0.0
Fixed in
6.0.0
References Updated Sep 20, 2024 · Source: OSV.dev
CVE-2021-43177
GHSA-jm35-h8q2-73mp
Apr 07, 2022
Improper one time password handling in devise-two-factor
5.3
/ 10
Medium
Network
High
Low
None
Unchanged
High
None
None
ImpactAs a result of an incomplete fix for CVE-2015-7225, in versions of devise-two-factor prior to 4.0.2 it is possible to reuse a One-Time-Password (OTP) for one (and only one) immediately trailing interval. PatchesThis vulnerability has been patched in version 4.0.2 which was released on March 24th, 2022. Individuals using this package are strongly encouraged to upgrade as soon as possible. Credit for discoveryBenoit Côté-Jodoin Michael Nipper - https://github.com/tinfoil/devise-two-factor/issues/106 Affected versions
1.0.0
1.0.1
1.0.2
1.1.0
2.0.0
2.0.1
2.1.0
2.2.0
2.2.1
3.0.0
3.0.1
3.0.2
+ 4 more Show less
3.0.3
3.1.0
4.0.0
4.0.1
Fixed in
4.0.2
References
Updated Aug 27, 2026 · Source: OSV.dev |
4.0.0
major
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
3.1.0
minor
1 CVE
CVE-2021-43177
GHSA-jm35-h8q2-73mp
Apr 07, 2022
Improper one time password handling in devise-two-factor
5.3
/ 10
Medium
Network
High
Low
None
Unchanged
High
None
None
ImpactAs a result of an incomplete fix for CVE-2015-7225, in versions of devise-two-factor prior to 4.0.2 it is possible to reuse a One-Time-Password (OTP) for one (and only one) immediately trailing interval. PatchesThis vulnerability has been patched in version 4.0.2 which was released on March 24th, 2022. Individuals using this package are strongly encouraged to upgrade as soon as possible. Credit for discoveryBenoit Côté-Jodoin Michael Nipper - https://github.com/tinfoil/devise-two-factor/issues/106 Affected versions
1.0.0
1.0.1
1.0.2
1.1.0
2.0.0
2.0.1
2.1.0
2.2.0
2.2.1
3.0.0
3.0.1
3.0.2
+ 4 more Show less
3.0.3
3.1.0
4.0.0
4.0.1
Fixed in
4.0.2
References
Updated Aug 27, 2026 · Source: OSV.dev |
3.1.0
minor
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
3.0.3
patch
1 CVE
CVE-2021-43177
GHSA-jm35-h8q2-73mp
Apr 07, 2022
Improper one time password handling in devise-two-factor
5.3
/ 10
Medium
Network
High
Low
None
Unchanged
High
None
None
ImpactAs a result of an incomplete fix for CVE-2015-7225, in versions of devise-two-factor prior to 4.0.2 it is possible to reuse a One-Time-Password (OTP) for one (and only one) immediately trailing interval. PatchesThis vulnerability has been patched in version 4.0.2 which was released on March 24th, 2022. Individuals using this package are strongly encouraged to upgrade as soon as possible. Credit for discoveryBenoit Côté-Jodoin Michael Nipper - https://github.com/tinfoil/devise-two-factor/issues/106 Affected versions
1.0.0
1.0.1
1.0.2
1.1.0
2.0.0
2.0.1
2.1.0
2.2.0
2.2.1
3.0.0
3.0.1
3.0.2
+ 4 more Show less
3.0.3
3.1.0
4.0.0
4.0.1
Fixed in
4.0.2
References
Updated Aug 27, 2026 · Source: OSV.dev |
3.0.3
patch
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
3.0.2
patch
1 CVE
CVE-2021-43177
GHSA-jm35-h8q2-73mp
Apr 07, 2022
Improper one time password handling in devise-two-factor
5.3
/ 10
Medium
Network
High
Low
None
Unchanged
High
None
None
ImpactAs a result of an incomplete fix for CVE-2015-7225, in versions of devise-two-factor prior to 4.0.2 it is possible to reuse a One-Time-Password (OTP) for one (and only one) immediately trailing interval. PatchesThis vulnerability has been patched in version 4.0.2 which was released on March 24th, 2022. Individuals using this package are strongly encouraged to upgrade as soon as possible. Credit for discoveryBenoit Côté-Jodoin Michael Nipper - https://github.com/tinfoil/devise-two-factor/issues/106 Affected versions
1.0.0
1.0.1
1.0.2
1.1.0
2.0.0
2.0.1
2.1.0
2.2.0
2.2.1
3.0.0
3.0.1
3.0.2
+ 4 more Show less
3.0.3
3.1.0
4.0.0
4.0.1
Fixed in
4.0.2
References
Updated Aug 27, 2026 · Source: OSV.dev |
3.0.2
patch
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
3.0.1
patch
1 CVE
CVE-2021-43177
GHSA-jm35-h8q2-73mp
Apr 07, 2022
Improper one time password handling in devise-two-factor
5.3
/ 10
Medium
Network
High
Low
None
Unchanged
High
None
None
ImpactAs a result of an incomplete fix for CVE-2015-7225, in versions of devise-two-factor prior to 4.0.2 it is possible to reuse a One-Time-Password (OTP) for one (and only one) immediately trailing interval. PatchesThis vulnerability has been patched in version 4.0.2 which was released on March 24th, 2022. Individuals using this package are strongly encouraged to upgrade as soon as possible. Credit for discoveryBenoit Côté-Jodoin Michael Nipper - https://github.com/tinfoil/devise-two-factor/issues/106 Affected versions
1.0.0
1.0.1
1.0.2
1.1.0
2.0.0
2.0.1
2.1.0
2.2.0
2.2.1
3.0.0
3.0.1
3.0.2
+ 4 more Show less
3.0.3
3.1.0
4.0.0
4.0.1
Fixed in
4.0.2
References
Updated Aug 27, 2026 · Source: OSV.dev |
3.0.1
patch
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
3.0.0
major
1 CVE
CVE-2021-43177
GHSA-jm35-h8q2-73mp
Apr 07, 2022
Improper one time password handling in devise-two-factor
5.3
/ 10
Medium
Network
High
Low
None
Unchanged
High
None
None
ImpactAs a result of an incomplete fix for CVE-2015-7225, in versions of devise-two-factor prior to 4.0.2 it is possible to reuse a One-Time-Password (OTP) for one (and only one) immediately trailing interval. PatchesThis vulnerability has been patched in version 4.0.2 which was released on March 24th, 2022. Individuals using this package are strongly encouraged to upgrade as soon as possible. Credit for discoveryBenoit Côté-Jodoin Michael Nipper - https://github.com/tinfoil/devise-two-factor/issues/106 Affected versions
1.0.0
1.0.1
1.0.2
1.1.0
2.0.0
2.0.1
2.1.0
2.2.0
2.2.1
3.0.0
3.0.1
3.0.2
+ 4 more Show less
3.0.3
3.1.0
4.0.0
4.0.1
Fixed in
4.0.2
References
Updated Aug 27, 2026 · Source: OSV.dev |
3.0.0
major
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
2.2.1
patch
1 CVE
CVE-2021-43177
GHSA-jm35-h8q2-73mp
Apr 07, 2022
Improper one time password handling in devise-two-factor
5.3
/ 10
Medium
Network
High
Low
None
Unchanged
High
None
None
ImpactAs a result of an incomplete fix for CVE-2015-7225, in versions of devise-two-factor prior to 4.0.2 it is possible to reuse a One-Time-Password (OTP) for one (and only one) immediately trailing interval. PatchesThis vulnerability has been patched in version 4.0.2 which was released on March 24th, 2022. Individuals using this package are strongly encouraged to upgrade as soon as possible. Credit for discoveryBenoit Côté-Jodoin Michael Nipper - https://github.com/tinfoil/devise-two-factor/issues/106 Affected versions
1.0.0
1.0.1
1.0.2
1.1.0
2.0.0
2.0.1
2.1.0
2.2.0
2.2.1
3.0.0
3.0.1
3.0.2
+ 4 more Show less
3.0.3
3.1.0
4.0.0
4.0.1
Fixed in
4.0.2
References
Updated Aug 27, 2026 · Source: OSV.dev |
2.2.1
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
2.2.0
minor
1 CVE
CVE-2021-43177
GHSA-jm35-h8q2-73mp
Apr 07, 2022
Improper one time password handling in devise-two-factor
5.3
/ 10
Medium
Network
High
Low
None
Unchanged
High
None
None
ImpactAs a result of an incomplete fix for CVE-2015-7225, in versions of devise-two-factor prior to 4.0.2 it is possible to reuse a One-Time-Password (OTP) for one (and only one) immediately trailing interval. PatchesThis vulnerability has been patched in version 4.0.2 which was released on March 24th, 2022. Individuals using this package are strongly encouraged to upgrade as soon as possible. Credit for discoveryBenoit Côté-Jodoin Michael Nipper - https://github.com/tinfoil/devise-two-factor/issues/106 Affected versions
1.0.0
1.0.1
1.0.2
1.1.0
2.0.0
2.0.1
2.1.0
2.2.0
2.2.1
3.0.0
3.0.1
3.0.2
+ 4 more Show less
3.0.3
3.1.0
4.0.0
4.0.1
Fixed in
4.0.2
References
Updated Aug 27, 2026 · Source: OSV.dev |
2.2.0
minor
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
2.1.0
minor
1 CVE
CVE-2021-43177
GHSA-jm35-h8q2-73mp
Apr 07, 2022
Improper one time password handling in devise-two-factor
5.3
/ 10
Medium
Network
High
Low
None
Unchanged
High
None
None
ImpactAs a result of an incomplete fix for CVE-2015-7225, in versions of devise-two-factor prior to 4.0.2 it is possible to reuse a One-Time-Password (OTP) for one (and only one) immediately trailing interval. PatchesThis vulnerability has been patched in version 4.0.2 which was released on March 24th, 2022. Individuals using this package are strongly encouraged to upgrade as soon as possible. Credit for discoveryBenoit Côté-Jodoin Michael Nipper - https://github.com/tinfoil/devise-two-factor/issues/106 Affected versions
1.0.0
1.0.1
1.0.2
1.1.0
2.0.0
2.0.1
2.1.0
2.2.0
2.2.1
3.0.0
3.0.1
3.0.2
+ 4 more Show less
3.0.3
3.1.0
4.0.0
4.0.1
Fixed in
4.0.2
References
Updated Aug 27, 2026 · Source: OSV.dev |
2.1.0
minor
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
2.0.1
patch
1 CVE
CVE-2021-43177
GHSA-jm35-h8q2-73mp
Apr 07, 2022
Improper one time password handling in devise-two-factor
5.3
/ 10
Medium
Network
High
Low
None
Unchanged
High
None
None
ImpactAs a result of an incomplete fix for CVE-2015-7225, in versions of devise-two-factor prior to 4.0.2 it is possible to reuse a One-Time-Password (OTP) for one (and only one) immediately trailing interval. PatchesThis vulnerability has been patched in version 4.0.2 which was released on March 24th, 2022. Individuals using this package are strongly encouraged to upgrade as soon as possible. Credit for discoveryBenoit Côté-Jodoin Michael Nipper - https://github.com/tinfoil/devise-two-factor/issues/106 Affected versions
1.0.0
1.0.1
1.0.2
1.1.0
2.0.0
2.0.1
2.1.0
2.2.0
2.2.1
3.0.0
3.0.1
3.0.2
+ 4 more Show less
3.0.3
3.1.0
4.0.0
4.0.1
Fixed in
4.0.2
References
Updated Aug 27, 2026 · Source: OSV.dev |
2.0.1
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
2.0.0
major
1 CVE
CVE-2021-43177
GHSA-jm35-h8q2-73mp
Apr 07, 2022
Improper one time password handling in devise-two-factor
5.3
/ 10
Medium
Network
High
Low
None
Unchanged
High
None
None
ImpactAs a result of an incomplete fix for CVE-2015-7225, in versions of devise-two-factor prior to 4.0.2 it is possible to reuse a One-Time-Password (OTP) for one (and only one) immediately trailing interval. PatchesThis vulnerability has been patched in version 4.0.2 which was released on March 24th, 2022. Individuals using this package are strongly encouraged to upgrade as soon as possible. Credit for discoveryBenoit Côté-Jodoin Michael Nipper - https://github.com/tinfoil/devise-two-factor/issues/106 Affected versions
1.0.0
1.0.1
1.0.2
1.1.0
2.0.0
2.0.1
2.1.0
2.2.0
2.2.1
3.0.0
3.0.1
3.0.2
+ 4 more Show less
3.0.3
3.1.0
4.0.0
4.0.1
Fixed in
4.0.2
References
Updated Aug 27, 2026 · Source: OSV.dev |
2.0.0
major
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
1.1.0
minor
2 CVEs
CVE-2021-43177
GHSA-jm35-h8q2-73mp
Apr 07, 2022
Improper one time password handling in devise-two-factor
5.3
/ 10
Medium
Network
High
Low
None
Unchanged
High
None
None
ImpactAs a result of an incomplete fix for CVE-2015-7225, in versions of devise-two-factor prior to 4.0.2 it is possible to reuse a One-Time-Password (OTP) for one (and only one) immediately trailing interval. PatchesThis vulnerability has been patched in version 4.0.2 which was released on March 24th, 2022. Individuals using this package are strongly encouraged to upgrade as soon as possible. Credit for discoveryBenoit Côté-Jodoin Michael Nipper - https://github.com/tinfoil/devise-two-factor/issues/106 Affected versions
1.0.0
1.0.1
1.0.2
1.1.0
2.0.0
2.0.1
2.1.0
2.2.0
2.2.1
3.0.0
3.0.1
3.0.2
+ 4 more Show less
3.0.3
3.1.0
4.0.0
4.0.1
Fixed in
4.0.2
References
Updated Aug 27, 2026 · Source: OSV.dev
CVE-2015-7225
GHSA-x489-jjwm-52g7
Aug 28, 2018
Tinfoil Devise-two-factor does not "burn" a successfully validated one-time password (OTP)
5.3
/ 10
Medium
Network
High
Low
None
Unchanged
High
None
None
Tinfoil Devise-two-factor before 2.0.0 does not strictly follow RFC 6238 § 5.2 and does not "burn" a successfully validated one-time password (aka OTP), which allows physically proximate attackers with a target user's login credentials to log in as said user by obtaining the OTP through performing a man-in-the-middle attack between the provider and verifier, or "shoulder surfing", and replaying the OTP in the current time-step. Affected versions
1.0.0
1.0.1
1.0.2
1.1.0
Fixed in
2.0.0
References
Updated Dec 08, 2024 · Source: OSV.dev |
1.1.0
minor
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
1.0.2
patch
2 CVEs
CVE-2021-43177
GHSA-jm35-h8q2-73mp
Apr 07, 2022
Improper one time password handling in devise-two-factor
5.3
/ 10
Medium
Network
High
Low
None
Unchanged
High
None
None
ImpactAs a result of an incomplete fix for CVE-2015-7225, in versions of devise-two-factor prior to 4.0.2 it is possible to reuse a One-Time-Password (OTP) for one (and only one) immediately trailing interval. PatchesThis vulnerability has been patched in version 4.0.2 which was released on March 24th, 2022. Individuals using this package are strongly encouraged to upgrade as soon as possible. Credit for discoveryBenoit Côté-Jodoin Michael Nipper - https://github.com/tinfoil/devise-two-factor/issues/106 Affected versions
1.0.0
1.0.1
1.0.2
1.1.0
2.0.0
2.0.1
2.1.0
2.2.0
2.2.1
3.0.0
3.0.1
3.0.2
+ 4 more Show less
3.0.3
3.1.0
4.0.0
4.0.1
Fixed in
4.0.2
References
Updated Aug 27, 2026 · Source: OSV.dev
CVE-2015-7225
GHSA-x489-jjwm-52g7
Aug 28, 2018
Tinfoil Devise-two-factor does not "burn" a successfully validated one-time password (OTP)
5.3
/ 10
Medium
Network
High
Low
None
Unchanged
High
None
None
Tinfoil Devise-two-factor before 2.0.0 does not strictly follow RFC 6238 § 5.2 and does not "burn" a successfully validated one-time password (aka OTP), which allows physically proximate attackers with a target user's login credentials to log in as said user by obtaining the OTP through performing a man-in-the-middle attack between the provider and verifier, or "shoulder surfing", and replaying the OTP in the current time-step. Affected versions
1.0.0
1.0.1
1.0.2
1.1.0
Fixed in
2.0.0
References
Updated Dec 08, 2024 · Source: OSV.dev |
1.0.2
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
1.0.1
patch
2 CVEs
CVE-2021-43177
GHSA-jm35-h8q2-73mp
Apr 07, 2022
Improper one time password handling in devise-two-factor
5.3
/ 10
Medium
Network
High
Low
None
Unchanged
High
None
None
ImpactAs a result of an incomplete fix for CVE-2015-7225, in versions of devise-two-factor prior to 4.0.2 it is possible to reuse a One-Time-Password (OTP) for one (and only one) immediately trailing interval. PatchesThis vulnerability has been patched in version 4.0.2 which was released on March 24th, 2022. Individuals using this package are strongly encouraged to upgrade as soon as possible. Credit for discoveryBenoit Côté-Jodoin Michael Nipper - https://github.com/tinfoil/devise-two-factor/issues/106 Affected versions
1.0.0
1.0.1
1.0.2
1.1.0
2.0.0
2.0.1
2.1.0
2.2.0
2.2.1
3.0.0
3.0.1
3.0.2
+ 4 more Show less
3.0.3
3.1.0
4.0.0
4.0.1
Fixed in
4.0.2
References
Updated Aug 27, 2026 · Source: OSV.dev
CVE-2015-7225
GHSA-x489-jjwm-52g7
Aug 28, 2018
Tinfoil Devise-two-factor does not "burn" a successfully validated one-time password (OTP)
5.3
/ 10
Medium
Network
High
Low
None
Unchanged
High
None
None
Tinfoil Devise-two-factor before 2.0.0 does not strictly follow RFC 6238 § 5.2 and does not "burn" a successfully validated one-time password (aka OTP), which allows physically proximate attackers with a target user's login credentials to log in as said user by obtaining the OTP through performing a man-in-the-middle attack between the provider and verifier, or "shoulder surfing", and replaying the OTP in the current time-step. Affected versions
1.0.0
1.0.1
1.0.2
1.1.0
Fixed in
2.0.0
References
Updated Dec 08, 2024 · Source: OSV.dev |
1.0.1
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
1.0.0
initial
3 CVEs
CVE-2024-8796
GHSA-qjxf-mc72-wjr2
Sep 17, 2024
Devise-Two-Factor Authentication Uses Insufficient Default OTP Shared Secret Length
Medium
Network
High
Low
None
SummaryUnder the default configuration, Devise-Two-Factor versions 1.0.0 or >= 4.0.0 & < 6.0.0 generate TOTP shared secrets that are 120 bits instead of the 128-bit minimum defined by RFC 4226. Using a shared secret shorter than the minimum to generate a multi-factor authentication code could make it easier for an attacker to guess the shared secret and generate valid TOTP codes. RemediationDevise-Two-Factor should be upgraded to version v6.0.0 as soon as possible. After upgrading, the length of shared secrets and TOTP URLs generated by the library will increase since the new shared secrets will be longer. If upgrading is not possible, you can override the default After upgrading or implementing the workaround, applications using Devise-Two-Factor may wish to migrate users to the new OTP length to provide increased protection for those accounts. Turning off OTP for users by setting BackgroundDevise-Two-Factor uses ROTP to generate shared secrets for TOTP. In ROTP < 5.0.0, the first argument to the Affected versions
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
5.0.0
5.1.0
1.0.0
Fixed in
6.0.0
References Updated Sep 20, 2024 · Source: OSV.dev
CVE-2021-43177
GHSA-jm35-h8q2-73mp
Apr 07, 2022
Improper one time password handling in devise-two-factor
5.3
/ 10
Medium
Network
High
Low
None
Unchanged
High
None
None
ImpactAs a result of an incomplete fix for CVE-2015-7225, in versions of devise-two-factor prior to 4.0.2 it is possible to reuse a One-Time-Password (OTP) for one (and only one) immediately trailing interval. PatchesThis vulnerability has been patched in version 4.0.2 which was released on March 24th, 2022. Individuals using this package are strongly encouraged to upgrade as soon as possible. Credit for discoveryBenoit Côté-Jodoin Michael Nipper - https://github.com/tinfoil/devise-two-factor/issues/106 Affected versions
1.0.0
1.0.1
1.0.2
1.1.0
2.0.0
2.0.1
2.1.0
2.2.0
2.2.1
3.0.0
3.0.1
3.0.2
+ 4 more Show less
3.0.3
3.1.0
4.0.0
4.0.1
Fixed in
4.0.2
References
Updated Aug 27, 2026 · Source: OSV.dev
CVE-2015-7225
GHSA-x489-jjwm-52g7
Aug 28, 2018
Tinfoil Devise-two-factor does not "burn" a successfully validated one-time password (OTP)
5.3
/ 10
Medium
Network
High
Low
None
Unchanged
High
None
None
Tinfoil Devise-two-factor before 2.0.0 does not strictly follow RFC 6238 § 5.2 and does not "burn" a successfully validated one-time password (aka OTP), which allows physically proximate attackers with a target user's login credentials to log in as said user by obtaining the OTP through performing a man-in-the-middle attack between the provider and verifier, or "shoulder surfing", and replaying the OTP in the current time-step. Affected versions
1.0.0
1.0.1
1.0.2
1.1.0
Fixed in
2.0.0
References
Updated Dec 08, 2024 · Source: OSV.dev |