NA

CVE-2023-34246

Published: 12/06/2023 Updated: 12/07/2023
CVSS v3 Base Score: 6.5 | Impact Score: 2.5 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

Doorkeeper is an OAuth 2 provider for Ruby on Rails / Grape. Prior to version 5.6.6, Doorkeeper automatically processes authorization requests without user consent for public clients that have been previous approved. Public clients are inherently vulnerable to impersonation, their identity cannot be assured. This issue is fixed in version 5.6.6.

Vulnerable Product Search on Vulmon Subscribe to Product

doorkeeper project doorkeeper

Vendor Advisories

Debian Bug report logs - #1038950 ruby-doorkeeper: CVE-2023-34246 Package: src:ruby-doorkeeper; Maintainer for src:ruby-doorkeeper is Debian Ruby Team <pkg-ruby-extras-maintainers@listsaliothdebianorg>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Fri, 23 Jun 2023 15:12:05 UTC Severity: important Tags: s ...