Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2021-43177
Description:As a result of an incomplete fix for CVE-2015-7225, in versions of devise-two-factor prior to 4.0.2 it is possible to reuse a One-Time- Password (OTP) for one (and only one) immediately trailing interval. CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N)
Test IDs: None available
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2021-43177
https://github.com/tinfoil/devise-two-factor/security/advisories/GHSA-jm35-h8q2-73mp
https://github.com/tinfoil/devise-two-factor/security/advisories/GHSA-jm35-h8q2-73mp




© 1998-2025 E-Soft Inc. All rights reserved.