Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2018-1000211

Опубликовано: 13 июл. 2018
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 5
CVSS3: 7.5

Описание

Doorkeeper version 4.2.0 and later contains a Incorrect Access Control vulnerability in Token revocation API's authorized method that can result in Access tokens are not revoked for public OAuth apps, leaking access until expiry.

РелизСтатусПримечание
artful

ignored

end of life
bionic

ignored

end of standard support, was needs-triage
cosmic

ignored

end of life
devel

not-affected

4.4.2-1
disco

not-affected

4.4.2-1
eoan

not-affected

4.4.2-1
esm-apps-legacy/xenial

not-affected

code not present
esm-apps/bionic

ignored

changes too intrusive
esm-apps/focal

not-affected

4.4.2-1
esm-apps/jammy

not-affected

4.4.2-1

Показывать по

EPSS

Процентиль: 75%
0.01597
Низкий

5 Medium

CVSS2

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
около 8 лет назад

Doorkeeper version 4.2.0 and later contains a Incorrect Access Control vulnerability in Token revocation API's authorized method that can result in Access tokens are not revoked for public OAuth apps, leaking access until expiry.

CVSS3: 7.5
debian
около 8 лет назад

Doorkeeper version 4.2.0 and later contains a Incorrect Access Control ...

CVSS3: 7.5
github
около 8 лет назад

Doorkeeper subject to Incorrect Permission Assignment

EPSS

Процентиль: 75%
0.01597
Низкий

5 Medium

CVSS2

7.5 High

CVSS3