The Doorkeeper gem before 4.2.0 for Ruby might allow remote attackers to conduct replay attacks or revoke arbitrary tokens by leveraging failure to implement the OAuth 2.0 Token Revocation specification.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Doorkeeper | Doorkeeper_project | * | 4.1.0 (including) |
| Ruby-doorkeeper | Ubuntu | esm-apps/xenial | * |
| Ruby-doorkeeper | Ubuntu | upstream | * |
| Ruby-doorkeeper | Ubuntu | xenial | * |