Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-694m-jhr9-pf77

Опубликовано: 13 авг. 2018
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Doorkeeper subject to Incorrect Permission Assignment

Doorkeeper version 4.2.0 and later contains a Incorrect Access Control vulnerability in Token revocation API's authorized method that can result in Access tokens are not revoked for public OAuth apps, leaking access until expiry.

Пакеты

Наименование

doorkeeper

rubygems
Затронутые версииВерсия исправления

>= 4.2.0, < 4.4.0

4.4.0

EPSS

Процентиль: 50%
0.00265
Низкий

7.5 High

CVSS3

Дефекты

CWE-732

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 7 лет назад

Doorkeeper version 4.2.0 and later contains a Incorrect Access Control vulnerability in Token revocation API's authorized method that can result in Access tokens are not revoked for public OAuth apps, leaking access until expiry.

CVSS3: 7.5
nvd
больше 7 лет назад

Doorkeeper version 4.2.0 and later contains a Incorrect Access Control vulnerability in Token revocation API's authorized method that can result in Access tokens are not revoked for public OAuth apps, leaking access until expiry.

CVSS3: 7.5
debian
больше 7 лет назад

Doorkeeper version 4.2.0 and later contains a Incorrect Access Control ...

EPSS

Процентиль: 50%
0.00265
Низкий

7.5 High

CVSS3

Дефекты

CWE-732