devise_masquerade
devise masquerade library
Activity
- Latest release
- 1y ago
- Total releases
- 56
- Cadence
- ~26 days
- Last 12 months
- 0
Details
- License
- MIT
- First release
- Nov 19, 2012
| Version | Released | |
|---|---|---|
2.1.4
patch
| ||
2.1.3
patch
| ||
2.1.2
patch
| ||
2.1.0
minor
| ||
2.0.3
patch
| ||
2.0.2
patch
| ||
2.0.1
patch
| ||
2.0.0
major
| ||
1.3.12
patch
| ||
1.3.11
patch
| ||
1.3.10
patch
| ||
1.3.9
patch
| ||
1.3.8
patch
| ||
1.3.7
patch
| ||
1.3.6
patch
| ||
1.3.5
patch
| ||
1.3.4
patch
| ||
1.3.3
patch
| ||
1.3.2
patch
| ||
1.3.0
minor
1 CVE
CVE-2021-28680
GHSA-25f5-gc4h-hc22
Dec 08, 2021
Improper Privilege Management in devise_masquerade
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The devise_masquerade gem before 1.3 allows certain attacks when a password's salt is unknown. An application that uses this gem to let administrators masquerade/impersonate users loses one layer of security protection compared to a situation where Devise (without this extension) is used. If the server-side Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
+ 24 more Show less
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
1.0.0
1.1.0
1.2.0
1.3.0
Fixed in
1.3.1
References
Updated Feb 18, 2024 · Source: OSV.dev | ||
1.3.1
patch
| ||
1.2.0
minor
1 CVE
CVE-2021-28680
GHSA-25f5-gc4h-hc22
Dec 08, 2021
Improper Privilege Management in devise_masquerade
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The devise_masquerade gem before 1.3 allows certain attacks when a password's salt is unknown. An application that uses this gem to let administrators masquerade/impersonate users loses one layer of security protection compared to a situation where Devise (without this extension) is used. If the server-side Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
+ 24 more Show less
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
1.0.0
1.1.0
1.2.0
1.3.0
Fixed in
1.3.1
References
Updated Feb 18, 2024 · Source: OSV.dev | ||
1.1.0
minor
1 CVE
CVE-2021-28680
GHSA-25f5-gc4h-hc22
Dec 08, 2021
Improper Privilege Management in devise_masquerade
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The devise_masquerade gem before 1.3 allows certain attacks when a password's salt is unknown. An application that uses this gem to let administrators masquerade/impersonate users loses one layer of security protection compared to a situation where Devise (without this extension) is used. If the server-side Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
+ 24 more Show less
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
1.0.0
1.1.0
1.2.0
1.3.0
Fixed in
1.3.1
References
Updated Feb 18, 2024 · Source: OSV.dev | ||
1.0.0
major
1 CVE
CVE-2021-28680
GHSA-25f5-gc4h-hc22
Dec 08, 2021
Improper Privilege Management in devise_masquerade
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The devise_masquerade gem before 1.3 allows certain attacks when a password's salt is unknown. An application that uses this gem to let administrators masquerade/impersonate users loses one layer of security protection compared to a situation where Devise (without this extension) is used. If the server-side Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
+ 24 more Show less
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
1.0.0
1.1.0
1.2.0
1.3.0
Fixed in
1.3.1
References
Updated Feb 18, 2024 · Source: OSV.dev | ||
0.6.5
patch
1 CVE
CVE-2021-28680
GHSA-25f5-gc4h-hc22
Dec 08, 2021
Improper Privilege Management in devise_masquerade
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The devise_masquerade gem before 1.3 allows certain attacks when a password's salt is unknown. An application that uses this gem to let administrators masquerade/impersonate users loses one layer of security protection compared to a situation where Devise (without this extension) is used. If the server-side Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
+ 24 more Show less
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
1.0.0
1.1.0
1.2.0
1.3.0
Fixed in
1.3.1
References
Updated Feb 18, 2024 · Source: OSV.dev | ||
0.6.4
patch
1 CVE
CVE-2021-28680
GHSA-25f5-gc4h-hc22
Dec 08, 2021
Improper Privilege Management in devise_masquerade
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The devise_masquerade gem before 1.3 allows certain attacks when a password's salt is unknown. An application that uses this gem to let administrators masquerade/impersonate users loses one layer of security protection compared to a situation where Devise (without this extension) is used. If the server-side Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
+ 24 more Show less
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
1.0.0
1.1.0
1.2.0
1.3.0
Fixed in
1.3.1
References
Updated Feb 18, 2024 · Source: OSV.dev | ||
0.6.3
patch
1 CVE
CVE-2021-28680
GHSA-25f5-gc4h-hc22
Dec 08, 2021
Improper Privilege Management in devise_masquerade
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The devise_masquerade gem before 1.3 allows certain attacks when a password's salt is unknown. An application that uses this gem to let administrators masquerade/impersonate users loses one layer of security protection compared to a situation where Devise (without this extension) is used. If the server-side Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
+ 24 more Show less
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
1.0.0
1.1.0
1.2.0
1.3.0
Fixed in
1.3.1
References
Updated Feb 18, 2024 · Source: OSV.dev | ||
0.6.2
patch
1 CVE
CVE-2021-28680
GHSA-25f5-gc4h-hc22
Dec 08, 2021
Improper Privilege Management in devise_masquerade
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The devise_masquerade gem before 1.3 allows certain attacks when a password's salt is unknown. An application that uses this gem to let administrators masquerade/impersonate users loses one layer of security protection compared to a situation where Devise (without this extension) is used. If the server-side Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
+ 24 more Show less
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
1.0.0
1.1.0
1.2.0
1.3.0
Fixed in
1.3.1
References
Updated Feb 18, 2024 · Source: OSV.dev | ||
0.6.1
patch
1 CVE
CVE-2021-28680
GHSA-25f5-gc4h-hc22
Dec 08, 2021
Improper Privilege Management in devise_masquerade
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The devise_masquerade gem before 1.3 allows certain attacks when a password's salt is unknown. An application that uses this gem to let administrators masquerade/impersonate users loses one layer of security protection compared to a situation where Devise (without this extension) is used. If the server-side Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
+ 24 more Show less
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
1.0.0
1.1.0
1.2.0
1.3.0
Fixed in
1.3.1
References
Updated Feb 18, 2024 · Source: OSV.dev | ||
0.6.0
minor
1 CVE
CVE-2021-28680
GHSA-25f5-gc4h-hc22
Dec 08, 2021
Improper Privilege Management in devise_masquerade
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The devise_masquerade gem before 1.3 allows certain attacks when a password's salt is unknown. An application that uses this gem to let administrators masquerade/impersonate users loses one layer of security protection compared to a situation where Devise (without this extension) is used. If the server-side Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
+ 24 more Show less
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
1.0.0
1.1.0
1.2.0
1.3.0
Fixed in
1.3.1
References
Updated Feb 18, 2024 · Source: OSV.dev | ||
0.5.3
patch
1 CVE
CVE-2021-28680
GHSA-25f5-gc4h-hc22
Dec 08, 2021
Improper Privilege Management in devise_masquerade
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The devise_masquerade gem before 1.3 allows certain attacks when a password's salt is unknown. An application that uses this gem to let administrators masquerade/impersonate users loses one layer of security protection compared to a situation where Devise (without this extension) is used. If the server-side Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
+ 24 more Show less
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
1.0.0
1.1.0
1.2.0
1.3.0
Fixed in
1.3.1
References
Updated Feb 18, 2024 · Source: OSV.dev | ||
0.5.2
patch
1 CVE
CVE-2021-28680
GHSA-25f5-gc4h-hc22
Dec 08, 2021
Improper Privilege Management in devise_masquerade
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The devise_masquerade gem before 1.3 allows certain attacks when a password's salt is unknown. An application that uses this gem to let administrators masquerade/impersonate users loses one layer of security protection compared to a situation where Devise (without this extension) is used. If the server-side Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
+ 24 more Show less
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
1.0.0
1.1.0
1.2.0
1.3.0
Fixed in
1.3.1
References
Updated Feb 18, 2024 · Source: OSV.dev | ||
0.5.0
minor
1 CVE
CVE-2021-28680
GHSA-25f5-gc4h-hc22
Dec 08, 2021
Improper Privilege Management in devise_masquerade
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The devise_masquerade gem before 1.3 allows certain attacks when a password's salt is unknown. An application that uses this gem to let administrators masquerade/impersonate users loses one layer of security protection compared to a situation where Devise (without this extension) is used. If the server-side Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
+ 24 more Show less
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
1.0.0
1.1.0
1.2.0
1.3.0
Fixed in
1.3.1
References
Updated Feb 18, 2024 · Source: OSV.dev | ||
0.5.1
patch
1 CVE
CVE-2021-28680
GHSA-25f5-gc4h-hc22
Dec 08, 2021
Improper Privilege Management in devise_masquerade
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The devise_masquerade gem before 1.3 allows certain attacks when a password's salt is unknown. An application that uses this gem to let administrators masquerade/impersonate users loses one layer of security protection compared to a situation where Devise (without this extension) is used. If the server-side Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
+ 24 more Show less
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
1.0.0
1.1.0
1.2.0
1.3.0
Fixed in
1.3.1
References
Updated Feb 18, 2024 · Source: OSV.dev | ||
0.4.0
minor
1 CVE
CVE-2021-28680
GHSA-25f5-gc4h-hc22
Dec 08, 2021
Improper Privilege Management in devise_masquerade
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The devise_masquerade gem before 1.3 allows certain attacks when a password's salt is unknown. An application that uses this gem to let administrators masquerade/impersonate users loses one layer of security protection compared to a situation where Devise (without this extension) is used. If the server-side Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
+ 24 more Show less
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
1.0.0
1.1.0
1.2.0
1.3.0
Fixed in
1.3.1
References
Updated Feb 18, 2024 · Source: OSV.dev | ||
0.3.1
patch
1 CVE
CVE-2021-28680
GHSA-25f5-gc4h-hc22
Dec 08, 2021
Improper Privilege Management in devise_masquerade
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The devise_masquerade gem before 1.3 allows certain attacks when a password's salt is unknown. An application that uses this gem to let administrators masquerade/impersonate users loses one layer of security protection compared to a situation where Devise (without this extension) is used. If the server-side Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
+ 24 more Show less
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
1.0.0
1.1.0
1.2.0
1.3.0
Fixed in
1.3.1
References
Updated Feb 18, 2024 · Source: OSV.dev | ||
0.3.0
minor
1 CVE
CVE-2021-28680
GHSA-25f5-gc4h-hc22
Dec 08, 2021
Improper Privilege Management in devise_masquerade
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The devise_masquerade gem before 1.3 allows certain attacks when a password's salt is unknown. An application that uses this gem to let administrators masquerade/impersonate users loses one layer of security protection compared to a situation where Devise (without this extension) is used. If the server-side Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
+ 24 more Show less
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
1.0.0
1.1.0
1.2.0
1.3.0
Fixed in
1.3.1
References
Updated Feb 18, 2024 · Source: OSV.dev | ||
0.2.0
minor
1 CVE
CVE-2021-28680
GHSA-25f5-gc4h-hc22
Dec 08, 2021
Improper Privilege Management in devise_masquerade
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The devise_masquerade gem before 1.3 allows certain attacks when a password's salt is unknown. An application that uses this gem to let administrators masquerade/impersonate users loses one layer of security protection compared to a situation where Devise (without this extension) is used. If the server-side Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
+ 24 more Show less
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
1.0.0
1.1.0
1.2.0
1.3.0
Fixed in
1.3.1
References
Updated Feb 18, 2024 · Source: OSV.dev | ||
0.1.8
patch
1 CVE
CVE-2021-28680
GHSA-25f5-gc4h-hc22
Dec 08, 2021
Improper Privilege Management in devise_masquerade
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The devise_masquerade gem before 1.3 allows certain attacks when a password's salt is unknown. An application that uses this gem to let administrators masquerade/impersonate users loses one layer of security protection compared to a situation where Devise (without this extension) is used. If the server-side Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
+ 24 more Show less
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
1.0.0
1.1.0
1.2.0
1.3.0
Fixed in
1.3.1
References
Updated Feb 18, 2024 · Source: OSV.dev | ||
0.1.7
patch
1 CVE
CVE-2021-28680
GHSA-25f5-gc4h-hc22
Dec 08, 2021
Improper Privilege Management in devise_masquerade
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The devise_masquerade gem before 1.3 allows certain attacks when a password's salt is unknown. An application that uses this gem to let administrators masquerade/impersonate users loses one layer of security protection compared to a situation where Devise (without this extension) is used. If the server-side Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
+ 24 more Show less
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
1.0.0
1.1.0
1.2.0
1.3.0
Fixed in
1.3.1
References
Updated Feb 18, 2024 · Source: OSV.dev | ||
0.1.6
patch
1 CVE
CVE-2021-28680
GHSA-25f5-gc4h-hc22
Dec 08, 2021
Improper Privilege Management in devise_masquerade
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The devise_masquerade gem before 1.3 allows certain attacks when a password's salt is unknown. An application that uses this gem to let administrators masquerade/impersonate users loses one layer of security protection compared to a situation where Devise (without this extension) is used. If the server-side Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
+ 24 more Show less
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
1.0.0
1.1.0
1.2.0
1.3.0
Fixed in
1.3.1
References
Updated Feb 18, 2024 · Source: OSV.dev | ||
0.1.5
patch
1 CVE
CVE-2021-28680
GHSA-25f5-gc4h-hc22
Dec 08, 2021
Improper Privilege Management in devise_masquerade
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The devise_masquerade gem before 1.3 allows certain attacks when a password's salt is unknown. An application that uses this gem to let administrators masquerade/impersonate users loses one layer of security protection compared to a situation where Devise (without this extension) is used. If the server-side Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
+ 24 more Show less
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
1.0.0
1.1.0
1.2.0
1.3.0
Fixed in
1.3.1
References
Updated Feb 18, 2024 · Source: OSV.dev | ||
0.1.4
patch
1 CVE
CVE-2021-28680
GHSA-25f5-gc4h-hc22
Dec 08, 2021
Improper Privilege Management in devise_masquerade
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The devise_masquerade gem before 1.3 allows certain attacks when a password's salt is unknown. An application that uses this gem to let administrators masquerade/impersonate users loses one layer of security protection compared to a situation where Devise (without this extension) is used. If the server-side Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
+ 24 more Show less
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
1.0.0
1.1.0
1.2.0
1.3.0
Fixed in
1.3.1
References
Updated Feb 18, 2024 · Source: OSV.dev | ||
0.1.3
patch
1 CVE
CVE-2021-28680
GHSA-25f5-gc4h-hc22
Dec 08, 2021
Improper Privilege Management in devise_masquerade
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The devise_masquerade gem before 1.3 allows certain attacks when a password's salt is unknown. An application that uses this gem to let administrators masquerade/impersonate users loses one layer of security protection compared to a situation where Devise (without this extension) is used. If the server-side Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
+ 24 more Show less
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
1.0.0
1.1.0
1.2.0
1.3.0
Fixed in
1.3.1
References
Updated Feb 18, 2024 · Source: OSV.dev | ||
0.1.1
patch
1 CVE
CVE-2021-28680
GHSA-25f5-gc4h-hc22
Dec 08, 2021
Improper Privilege Management in devise_masquerade
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The devise_masquerade gem before 1.3 allows certain attacks when a password's salt is unknown. An application that uses this gem to let administrators masquerade/impersonate users loses one layer of security protection compared to a situation where Devise (without this extension) is used. If the server-side Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
+ 24 more Show less
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
1.0.0
1.1.0
1.2.0
1.3.0
Fixed in
1.3.1
References
Updated Feb 18, 2024 · Source: OSV.dev | ||
0.1.2
patch
1 CVE
CVE-2021-28680
GHSA-25f5-gc4h-hc22
Dec 08, 2021
Improper Privilege Management in devise_masquerade
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The devise_masquerade gem before 1.3 allows certain attacks when a password's salt is unknown. An application that uses this gem to let administrators masquerade/impersonate users loses one layer of security protection compared to a situation where Devise (without this extension) is used. If the server-side Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
+ 24 more Show less
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
1.0.0
1.1.0
1.2.0
1.3.0
Fixed in
1.3.1
References
Updated Feb 18, 2024 · Source: OSV.dev | ||
0.1.0
minor
1 CVE
CVE-2021-28680
GHSA-25f5-gc4h-hc22
Dec 08, 2021
Improper Privilege Management in devise_masquerade
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The devise_masquerade gem before 1.3 allows certain attacks when a password's salt is unknown. An application that uses this gem to let administrators masquerade/impersonate users loses one layer of security protection compared to a situation where Devise (without this extension) is used. If the server-side Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
+ 24 more Show less
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
1.0.0
1.1.0
1.2.0
1.3.0
Fixed in
1.3.1
References
Updated Feb 18, 2024 · Source: OSV.dev | ||
0.0.9
patch
1 CVE
CVE-2021-28680
GHSA-25f5-gc4h-hc22
Dec 08, 2021
Improper Privilege Management in devise_masquerade
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The devise_masquerade gem before 1.3 allows certain attacks when a password's salt is unknown. An application that uses this gem to let administrators masquerade/impersonate users loses one layer of security protection compared to a situation where Devise (without this extension) is used. If the server-side Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
+ 24 more Show less
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
1.0.0
1.1.0
1.2.0
1.3.0
Fixed in
1.3.1
References
Updated Feb 18, 2024 · Source: OSV.dev | ||
0.0.8
patch
1 CVE
CVE-2021-28680
GHSA-25f5-gc4h-hc22
Dec 08, 2021
Improper Privilege Management in devise_masquerade
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The devise_masquerade gem before 1.3 allows certain attacks when a password's salt is unknown. An application that uses this gem to let administrators masquerade/impersonate users loses one layer of security protection compared to a situation where Devise (without this extension) is used. If the server-side Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
+ 24 more Show less
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
1.0.0
1.1.0
1.2.0
1.3.0
Fixed in
1.3.1
References
Updated Feb 18, 2024 · Source: OSV.dev | ||
0.0.7
patch
1 CVE
CVE-2021-28680
GHSA-25f5-gc4h-hc22
Dec 08, 2021
Improper Privilege Management in devise_masquerade
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The devise_masquerade gem before 1.3 allows certain attacks when a password's salt is unknown. An application that uses this gem to let administrators masquerade/impersonate users loses one layer of security protection compared to a situation where Devise (without this extension) is used. If the server-side Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
+ 24 more Show less
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
1.0.0
1.1.0
1.2.0
1.3.0
Fixed in
1.3.1
References
Updated Feb 18, 2024 · Source: OSV.dev |