CVE-2019-16109: Plataformatec Devise
Medium severity, CVSS 5.3. EPSS: 1.8% chance of exploitation in the next 30 days.
An issue was discovered in Plataformatec Devise before 4.7.1. It confirms accounts upon receiving a request with a blank confirmation_token, if a database record has a blank value in the confirmation_token column. (However, there is no scenario within Devise itself in which such database records would exist.)
Affected products
- Plataformatec Devise: before 4.7.1 (fixed in 4.7.1)
Published 2019-09-08. Last modified 2026-06-17.