Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-34246

Опубликовано: 12 июн. 2023
Источник: debian
EPSS Низкий

Описание

Doorkeeper is an OAuth 2 provider for Ruby on Rails / Grape. Prior to version 5.6.6, Doorkeeper automatically processes authorization requests without user consent for public clients that have been previous approved. Public clients are inherently vulnerable to impersonation, their identity cannot be assured. This issue is fixed in version 5.6.6.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ruby-doorkeeperfixed5.6.6-1experimentalpackage
ruby-doorkeeperfixed5.6.6-2package
ruby-doorkeeperfixed5.5.0-2+deb12u1bookwormpackage

Примечания

  • https://github.com/doorkeeper-gem/doorkeeper/security/advisories/GHSA-7w2c-w47h-789w

  • https://github.com/doorkeeper-gem/doorkeeper/issues/1589

  • https://github.com/doorkeeper-gem/doorkeeper/pull/1646

  • Fixed by: https://github.com/doorkeeper-gem/doorkeeper/commit/f202079baac4c978a01ccc9a45d78fde368ac907 (v5.6.6)

EPSS

Процентиль: 59%
0.00376
Низкий

Связанные уязвимости

CVSS3: 4.2
ubuntu
больше 2 лет назад

Doorkeeper is an OAuth 2 provider for Ruby on Rails / Grape. Prior to version 5.6.6, Doorkeeper automatically processes authorization requests without user consent for public clients that have been previous approved. Public clients are inherently vulnerable to impersonation, their identity cannot be assured. This issue is fixed in version 5.6.6.

CVSS3: 4.2
nvd
больше 2 лет назад

Doorkeeper is an OAuth 2 provider for Ruby on Rails / Grape. Prior to version 5.6.6, Doorkeeper automatically processes authorization requests without user consent for public clients that have been previous approved. Public clients are inherently vulnerable to impersonation, their identity cannot be assured. This issue is fixed in version 5.6.6.

CVSS3: 4.2
github
больше 2 лет назад

Doorkeeper Improper Authentication vulnerability

EPSS

Процентиль: 59%
0.00376
Низкий