Tinfoilsecurity develops authentication and security libraries, with a focused footprint centered on the Devise Two-Factor product for adding multi-factor authentication to web applications. The observed vulnerability signal reflects entropy and randomness-generation concerns in cryptographic authentication contexts, which are characteristic of security library implementations. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tinfoilsecurity over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-43177MEDIUM As a result of an incomplete fix for CVE-2015-7225, in versions of devise-two-factor prior to 4.0.2 it is possible to reuse a One-Time-Password (OTP) for one (and only one) immedia | Apr 11, 2022 | 5.3 | 20 | NO | NO |
CVE-2024-8796MEDIUM Under the default configuration, Devise-Two-Factor versions >= 2.2.0 & < 6.0.0 generate TOTP shared secrets that are 120 bits instead of the 128-bit minimum defined by RFC 4226. Us | Sep 17, 2024 | 5.3 | 16 | NO | NO |
CVE-2015-7225MEDIUM Tinfoil Devise-two-factor before 2.0.0 does not strictly follow section 5.2 of RFC 6238 and does not "burn" a successfully validated one-time password (aka OTP), which allows remot | Sep 6, 2017 | 5.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tinfoilsecurity.
Media articles that mention a CVE ID that affects a product developed by Tinfoilsecurity — matched by CVE ID, not by vendor name.