CVE Vulnerabilities

CVE-2016-6582

Published: Jan 23, 2017 | Modified: Oct 09, 2018
CVSS 3.x
9.1
CRITICAL
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
CVSS 2.x
6.4 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

The Doorkeeper gem before 4.2.0 for Ruby might allow remote attackers to conduct replay attacks or revoke arbitrary tokens by leveraging failure to implement the OAuth 2.0 Token Revocation specification.

Affected Software

Name Vendor Start Version End Version
Doorkeeper Doorkeeper_project * 4.1.0 (including)
Ruby-doorkeeper Ubuntu esm-apps/xenial *
Ruby-doorkeeper Ubuntu upstream *
Ruby-doorkeeper Ubuntu xenial *

References