VDB
Sign up
CRITICAL9.1

GHSA-3m6r-39p3-jq25

Doorkeeper is vulnerable to replay attacks

Quick fix

GHSA-3m6r-39p3-jq25 — doorkeeper: upgrade to the fixed version with the command below.

bundle update doorkeeper

Details

The Doorkeeper gem before 4.2.0 for Ruby might allow remote attackers to conduct replay attacks or revoke arbitrary tokens by leveraging failure to implement the OAuth 2.0 Token Revocation specification.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/doorkeeper
Introduced in: 0Fixed in: 4.2.0
Fixbundle update doorkeeper

References