Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2023-34246

Опубликовано: 12 июн. 2023
Источник: ubuntu
Приоритет: high
EPSS Низкий
CVSS3: 4.2

Описание

Doorkeeper is an OAuth 2 provider for Ruby on Rails / Grape. Prior to version 5.6.6, Doorkeeper automatically processes authorization requests without user consent for public clients that have been previous approved. Public clients are inherently vulnerable to impersonation, their identity cannot be assured. This issue is fixed in version 5.6.6.

РелизСтатусПримечание
bionic

ignored

end of standard support
devel

not-affected

5.6.6-2
esm-apps/bionic

released

4.3.1-1ubuntu0.1~esm1
esm-apps/focal

released

5.0.2-2ubuntu0.1
esm-apps/jammy

released

5.5.0-2ubuntu0.22.04.1
esm-apps/noble

not-affected

5.6.6-2
esm-apps/xenial

released

2.2.1-1ubuntu0.1~esm1
focal

released

5.0.2-2ubuntu0.1
jammy

released

5.5.0-2ubuntu0.22.04.1
kinetic

released

5.5.0-2ubuntu0.22.10.1

Показывать по

РелизСтатусПримечание
bionic

ignored

end of standard support
devel

not-affected

code not present
esm-apps/bionic

not-affected

code not present
esm-apps/focal

not-affected

code not present
esm-apps/jammy

not-affected

code not present
esm-apps/noble

not-affected

code not present
focal

not-affected

code not present
jammy

not-affected

code not present
kinetic

not-affected

code not present
lunar

not-affected

code not present

Показывать по

EPSS

Процентиль: 59%
0.00376
Низкий

4.2 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.2
nvd
больше 2 лет назад

Doorkeeper is an OAuth 2 provider for Ruby on Rails / Grape. Prior to version 5.6.6, Doorkeeper automatically processes authorization requests without user consent for public clients that have been previous approved. Public clients are inherently vulnerable to impersonation, their identity cannot be assured. This issue is fixed in version 5.6.6.

CVSS3: 4.2
debian
больше 2 лет назад

Doorkeeper is an OAuth 2 provider for Ruby on Rails / Grape. Prior to ...

CVSS3: 4.2
github
больше 2 лет назад

Doorkeeper Improper Authentication vulnerability

EPSS

Процентиль: 59%
0.00376
Низкий

4.2 Medium

CVSS3