Plataformatec maintains a narrow set of Ruby authentication and form-handling libraries, Devise and Simple Form, that are embedded across many Rails applications and web services. The recurring vulnerability signal centers on input-validation and authentication-control weaknesses characteristic of libraries sitting at the boundary between user input and credential handling, including improper input validation, excessive authentication attempts, and race conditions in state-dependent logic. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Plataformatec over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-0233MEDIUM Devise gem 2.2.x before 2.2.3, 2.1.x before 2.1.3, 2.0.x before 2.0.5, and 1.5.x before 1.5.4 for Ruby, when using certain databases, does not properly perform type conversion when | Apr 25, 2013 | 6.8 | 39 | NO | YES |
CVE-2019-16676CRITICAL Plataformatec Simple Form has Incorrect Access Control in file_method? in lib/simple_form/form_builder.rb, because a user-supplied string is invoked as a method call. | Sep 30, 2019 | 9.8 | 30 | NO | NO |
CVE-2019-5421CRITICAL Plataformatec Devise version 4.5.0 and earlier, using the lockable module contains a CWE-367 vulnerability in The `Devise::Models::Lockable` class, more specifically at the `#incre | Apr 3, 2019 | 9.8 | 30 | NO | NO |
CVE-2019-16109MEDIUM An issue was discovered in Plataformatec Devise before 4.7.1. It confirms accounts upon receiving a request with a blank confirmation_token, if a database record has a blank value | Sep 8, 2019 | 5.3 | 20 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Plataformatec.
Media articles that mention a CVE ID that affects a product developed by Plataformatec — matched by CVE ID, not by vendor name.