CVE-2019-16109: Plataformatec Devise

Medium severity, CVSS 5.3. EPSS: 1.8% chance of exploitation in the next 30 days.

An issue was discovered in Plataformatec Devise before 4.7.1. It confirms accounts upon receiving a request with a blank confirmation_token, if a database record has a blank value in the confirmation_token column. (However, there is no scenario within Devise itself in which such database records would exist.)

Affected products

Published 2019-09-08. Last modified 2026-06-17.