CVE-2015-8314: Heartcombo Devise

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

The Devise gem before 3.5.4 for Ruby mishandles Remember Me cookies for sessions, which may allow an adversary to obtain unauthorized persistent application access.

Affected products

Published 2023-12-12. Last modified 2026-06-17.