CVE Vulnerabilities

CVE-2023-34246

Improper Authentication

Published: Jun 12, 2023 | Modified: Dec 09, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
HIGH

Doorkeeper is an OAuth 2 provider for Ruby on Rails / Grape. Prior to version 5.6.6, Doorkeeper automatically processes authorization requests without user consent for public clients that have been previous approved. Public clients are inherently vulnerable to impersonation, their identity cannot be assured. This issue is fixed in version 5.6.6.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Doorkeeper Doorkeeper_project * 5.6.6 (excluding)
Ruby-doorkeeper Ubuntu bionic *
Ruby-doorkeeper Ubuntu esm-apps/bionic *
Ruby-doorkeeper Ubuntu esm-apps/xenial *
Ruby-doorkeeper Ubuntu focal *
Ruby-doorkeeper Ubuntu jammy *
Ruby-doorkeeper Ubuntu kinetic *
Ruby-doorkeeper Ubuntu lunar *
Ruby-doorkeeper Ubuntu mantic *
Ruby-doorkeeper Ubuntu upstream *
Ruby-doorkeeper Ubuntu xenial *
Ruby-doorkeeper-openid-connect Ubuntu bionic *
Ruby-doorkeeper-openid-connect Ubuntu mantic *

Potential Mitigations

References