Sploitus

CVE-2019-16109

No indexed exploits for CVE-2019-16109 yet

An issue was discovered in Plataformatec Devise before 4.7.1. It confirms accounts upon receiving a request with a blank confirmation_token, if a database record has a blank value in the confirmation_token column. (However, there is no scenario within Devise itself in which such database records would exist.)

Affected products
Devise
Plataformatec Devise
< 4.7.1
Fix
Available
CVSS 3.1
5.3 MEDIUM
EPSS
1.8% (77th percentile)
NVD status
Modified
Published
2019-09-08
CVE-2019-16109 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2019-16109 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2019-16109 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.