Candidate: CVE-2015-7225 PublicDate: 2017-09-06 21:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-7225 http://www.openwall.com/lists/oss-security/2015/09/06/2 Description: Tinfoil Devise-two-factor before 2.0.0 does not strictly follow section 5.2 of RFC 6238 and does not "burn" a successfully validated one-time password (aka OTP), which allows remote or physically proximate attackers with a target user's login credentials to log in as said user by obtaining the OTP through performing a man-in-the-middle attack between the provider and verifier, or shoulder surfing, and replaying the OTP in the current time-step. Ubuntu-Description: Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=798466 Priority: medium Discovered-by: Viliam Holub Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N [5.3 MEDIUM] Patches_ruby-devise-two-factor: upstream: https://github.com/tinfoil/devise-two-factor/pull/43 upstream_ruby-devise-two-factor: released (2.0.0-1) precise_ruby-devise-two-factor: DNE precise/esm_ruby-devise-two-factor: DNE trusty_ruby-devise-two-factor: DNE trusty/esm_ruby-devise-two-factor: DNE vivid_ruby-devise-two-factor: DNE vivid/stable-phone-overlay_ruby-devise-two-factor: DNE vivid/ubuntu-core_ruby-devise-two-factor: DNE wily_ruby-devise-two-factor: ignored (reached end-of-life) xenial_ruby-devise-two-factor: not-affected (2.0.0-1) yakkety_ruby-devise-two-factor: ignored (reached end-of-life) zesty_ruby-devise-two-factor: ignored (reached end-of-life) artful_ruby-devise-two-factor: ignored (reached end-of-life) bionic_ruby-devise-two-factor: DNE cosmic_ruby-devise-two-factor: DNE devel_ruby-devise-two-factor: DNE