CVE-2015-8314

The Devise gem before 3.5.4 for Ruby mishandles Remember Me cookies for sessions, which may allow an adversary to obtain unauthorized persistent application access.

Scoring

Severity
HIGH
CVSS base score
7.5
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS probability
0.17%
Published
2023-12-12
Last modified
2026-09-17

Affected products

Markdown version · Browse all CVEs