{"id":"GHSA-jm35-h8q2-73mp","summary":"Improper one time password handling in devise-two-factor","details":"### Impact\nAs a result of an incomplete fix for CVE-2015-7225, in versions of devise-two-factor prior to 4.0.2 it is possible to reuse a One-Time-Password (OTP) for one (and only one) immediately trailing interval.\n \n### Patches\nThis vulnerability has been patched in version 4.0.2 which was released on March 24th, 2022. Individuals using this package are strongly encouraged to upgrade as soon as possible.\n\n### Credit for discovery\nBenoit Côté-Jodoin\nMichael Nipper - https://github.com/tinfoil/devise-two-factor/issues/106","aliases":["CVE-2021-43177"],"modified":"2026-08-27T03:56:00.293667065Z","published":"2022-04-07T22:09:03Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2022-04-07T22:09:03Z","nvd_published_at":"2022-04-11T20:15:00Z","cwe_ids":[],"severity":"MODERATE"},"references":[{"type":"WEB","url":"https://github.com/tinfoil/devise-two-factor/security/advisories/GHSA-jm35-h8q2-73mp"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-43177"},{"type":"WEB","url":"https://github.com/tinfoil/devise-two-factor/issues/106"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/devise-two-factor/CVE-2021-43177.yml"},{"type":"PACKAGE","url":"https://github.com/tinfoil/devise-two-factor"}],"affected":[{"package":{"name":"devise-two-factor","ecosystem":"RubyGems","purl":"pkg:gem/devise-two-factor"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.0.2"}]}],"versions":["1.0.0","1.0.1","1.0.2","1.1.0","2.0.0","2.0.1","2.1.0","2.2.0","2.2.1","3.0.0","3.0.1","3.0.2","3.0.3","3.1.0","4.0.0","4.0.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/04/GHSA-jm35-h8q2-73mp/GHSA-jm35-h8q2-73mp.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"}]}