--- gem: devise cve: 2013-0233 osvdb: 89642 url: http://osvdb.org/show/osvdb/89642 title: Devise Database Type Conversion Crafted Request Parsing Security Bypass date: 2013-01-28 description: | Devise contains a flaw that is triggered during when a type conversion error occurs during the parsing of a malformed request. With a specially crafted request, a remote attacker can bypass security restrictions. cvss_v2: 10.0 patched_versions: - ~> 1.5.4 - ~> 2.0.5 - ~> 2.1.3 - ">= 2.2.3"