Описание
Doorkeeper version 4.2.0 and later contains a Incorrect Access Control vulnerability in Token revocation API's authorized method that can result in Access tokens are not revoked for public OAuth apps, leaking access until expiry.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| ruby-doorkeeper | fixed | 4.4.2-1 | package | |
| ruby-doorkeeper | ignored | stretch | package |
Примечания
https://github.com/doorkeeper-gem/doorkeeper/issues/891
https://github.com/doorkeeper-gem/doorkeeper/pull/1119
https://github.com/doorkeeper-gem/doorkeeper/commit/16e76e666b63e0e5e2704dd45b59e426190ddc78 (v4.4.0)
Requires changes in the reverse dependencies
EPSS
Связанные уязвимости
Doorkeeper version 4.2.0 and later contains a Incorrect Access Control vulnerability in Token revocation API's authorized method that can result in Access tokens are not revoked for public OAuth apps, leaking access until expiry.
Doorkeeper version 4.2.0 and later contains a Incorrect Access Control vulnerability in Token revocation API's authorized method that can result in Access tokens are not revoked for public OAuth apps, leaking access until expiry.
Doorkeeper subject to Incorrect Permission Assignment
EPSS