CRITICAL9.1
GHSA-3m6r-39p3-jq25
Doorkeeper is vulnerable to replay attacks
Quick fix
GHSA-3m6r-39p3-jq25 — doorkeeper: upgrade to the fixed version with the command below.
bundle update doorkeeperDetails
The Doorkeeper gem before 4.2.0 for Ruby might allow remote attackers to conduct replay attacks or revoke arbitrary tokens by leveraging failure to implement the OAuth 2.0 Token Revocation specification.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2016-6582[ADVISORY]
- https://github.com/doorkeeper-gem/doorkeeper/issues/875[WEB]
- https://github.com/advisories/GHSA-3m6r-39p3-jq25[ADVISORY]
- https://github.com/doorkeeper-gem/doorkeeper[WEB]
- https://github.com/doorkeeper-gem/doorkeeper/releases/tag/v4.2.0[WEB]
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/doorkeeper/CVE-2016-6582.yml[WEB]
- https://web.archive.org/web/20170214021758/http://www.securityfocus.com/bid/92551[WEB]
- https://web.archive.org/web/20201207202519/http://www.securityfocus.com/archive/1/539268/100/0/threaded[WEB]
- http://packetstormsecurity.com/files/138430/Doorkeeper-4.1.0-Token-Revocation.html[WEB]
- http://seclists.org/fulldisclosure/2016/Aug/105[WEB]
- http://www.openwall.com/lists/oss-security/2016/08/19/2[WEB]