Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2018-1000211

Опубликовано: 13 июл. 2018
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 5
CVSS3: 7.5

Описание

Doorkeeper version 4.2.0 and later contains a Incorrect Access Control vulnerability in Token revocation API's authorized method that can result in Access tokens are not revoked for public OAuth apps, leaking access until expiry.

РелизСтатусПримечание
artful

ignored

end of life
bionic

ignored

end of standard support, was needs-triage
cosmic

ignored

end of life
devel

not-affected

4.4.2-1
disco

not-affected

4.4.2-1
eoan

not-affected

4.4.2-1
esm-apps/bionic

ignored

changes too intrusive
esm-apps/focal

not-affected

4.4.2-1
esm-apps/jammy

not-affected

4.4.2-1
esm-apps/noble

not-affected

4.4.2-1

Показывать по

EPSS

Процентиль: 51%
0.0028
Низкий

5 Medium

CVSS2

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
больше 7 лет назад

Doorkeeper version 4.2.0 and later contains a Incorrect Access Control vulnerability in Token revocation API's authorized method that can result in Access tokens are not revoked for public OAuth apps, leaking access until expiry.

CVSS3: 7.5
debian
больше 7 лет назад

Doorkeeper version 4.2.0 and later contains a Incorrect Access Control ...

CVSS3: 7.5
github
больше 7 лет назад

Doorkeeper subject to Incorrect Permission Assignment

EPSS

Процентиль: 51%
0.0028
Низкий

5 Medium

CVSS2

7.5 High

CVSS3