Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3m6r-39p3-jq25

Опубликовано: 24 окт. 2017
Источник: github
Github: Прошло ревью
CVSS3: 9.1

Описание

Doorkeeper is vulnerable to replay attacks

The Doorkeeper gem before 4.2.0 for Ruby might allow remote attackers to conduct replay attacks or revoke arbitrary tokens by leveraging failure to implement the OAuth 2.0 Token Revocation specification.

Пакеты

Наименование

doorkeeper

rubygems
Затронутые версииВерсия исправления

< 4.2.0

4.2.0

EPSS

Процентиль: 81%
0.01593
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-1254

Связанные уязвимости

CVSS3: 9.1
ubuntu
около 9 лет назад

The Doorkeeper gem before 4.2.0 for Ruby might allow remote attackers to conduct replay attacks or revoke arbitrary tokens by leveraging failure to implement the OAuth 2.0 Token Revocation specification.

CVSS3: 9.1
nvd
около 9 лет назад

The Doorkeeper gem before 4.2.0 for Ruby might allow remote attackers to conduct replay attacks or revoke arbitrary tokens by leveraging failure to implement the OAuth 2.0 Token Revocation specification.

CVSS3: 9.1
debian
около 9 лет назад

The Doorkeeper gem before 4.2.0 for Ruby might allow remote attackers ...

EPSS

Процентиль: 81%
0.01593
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-1254