Upgrade devise-two-factor and devise-pbkdf2-encryptable
Related to https://gitlab.com/gitlab-org/gitlab/-/issues/537195
What?
- Upgrades devise-two-factor and devise-pbkdf2
Why?
-
Our
devise-two-factorversion 4.1.1 has these 2 vulnerabilities: -
Our
devise-pbkdf2vendored gem depends ondevise-two-factorversion 4.1.1 so it also has to be updated
How to set up and validate locally
pbkdf2 is the fallback of bcrypt and is used in FIDO_mode
Follow these steps to verify.
MR acceptance checklist
Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.