CVE Vulnerabilities

CVE-2023-34246

Improper Authentication

Published: Jun 12, 2023 | Modified: Dec 09, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
HIGH
root.io logo minimus.io logo echo.ai logo

Doorkeeper is an OAuth 2 provider for Ruby on Rails / Grape. Prior to version 5.6.6, Doorkeeper automatically processes authorization requests without user consent for public clients that have been previous approved. Public clients are inherently vulnerable to impersonation, their identity cannot be assured. This issue is fixed in version 5.6.6.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

NameVendorStart VersionEnd Version
DoorkeeperDoorkeeper_project*5.6.6 (excluding)
Ruby-doorkeeperUbuntubionic*
Ruby-doorkeeperUbuntuesm-apps/bionic*
Ruby-doorkeeperUbuntuesm-apps/focal*
Ruby-doorkeeperUbuntuesm-apps/jammy*
Ruby-doorkeeperUbuntuesm-apps/xenial*
Ruby-doorkeeperUbuntufocal*
Ruby-doorkeeperUbuntujammy*
Ruby-doorkeeperUbuntukinetic*
Ruby-doorkeeperUbuntulunar*
Ruby-doorkeeperUbuntumantic*
Ruby-doorkeeperUbuntuupstream*
Ruby-doorkeeperUbuntuxenial*
Ruby-doorkeeper-openid-connectUbuntubionic*
Ruby-doorkeeper-openid-connectUbuntumantic*

Potential Mitigations

References