Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-34246

Опубликовано: 12 июн. 2023
Источник: nvd
CVSS3: 4.2
CVSS3: 6.5
EPSS Низкий

Описание

Doorkeeper is an OAuth 2 provider for Ruby on Rails / Grape. Prior to version 5.6.6, Doorkeeper automatically processes authorization requests without user consent for public clients that have been previous approved. Public clients are inherently vulnerable to impersonation, their identity cannot be assured. This issue is fixed in version 5.6.6.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:doorkeeper_project:doorkeeper:*:*:*:*:*:ruby:*:*
Версия до 5.6.6 (исключая)

EPSS

Процентиль: 59%
0.00376
Низкий

4.2 Medium

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-287
CWE-287

Связанные уязвимости

CVSS3: 4.2
ubuntu
больше 2 лет назад

Doorkeeper is an OAuth 2 provider for Ruby on Rails / Grape. Prior to version 5.6.6, Doorkeeper automatically processes authorization requests without user consent for public clients that have been previous approved. Public clients are inherently vulnerable to impersonation, their identity cannot be assured. This issue is fixed in version 5.6.6.

CVSS3: 4.2
debian
больше 2 лет назад

Doorkeeper is an OAuth 2 provider for Ruby on Rails / Grape. Prior to ...

CVSS3: 4.2
github
больше 2 лет назад

Doorkeeper Improper Authentication vulnerability

EPSS

Процентиль: 59%
0.00376
Низкий

4.2 Medium

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-287
CWE-287