Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-6582

Опубликовано: 23 янв. 2017
Источник: debian

Описание

The Doorkeeper gem before 4.2.0 for Ruby might allow remote attackers to conduct replay attacks or revoke arbitrary tokens by leveraging failure to implement the OAuth 2.0 Token Revocation specification.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ruby-doorkeeperfixed4.2.0-3package

Примечания

  • https://github.com/doorkeeper-gem/doorkeeper/commit/fb938051777a3c9cb071e96fc66458f8f615bd53

  • https://github.com/doorkeeper-gem/doorkeeper/issues/875

Связанные уязвимости

CVSS3: 9.1
ubuntu
около 9 лет назад

The Doorkeeper gem before 4.2.0 for Ruby might allow remote attackers to conduct replay attacks or revoke arbitrary tokens by leveraging failure to implement the OAuth 2.0 Token Revocation specification.

CVSS3: 9.1
nvd
около 9 лет назад

The Doorkeeper gem before 4.2.0 for Ruby might allow remote attackers to conduct replay attacks or revoke arbitrary tokens by leveraging failure to implement the OAuth 2.0 Token Revocation specification.

CVSS3: 9.1
github
больше 8 лет назад

Doorkeeper is vulnerable to replay attacks