VDB
Sign up
MEDIUM

GHSA-685w-vc84-wxcx

Doorkeeper vulnerable to Cross-site Request Forgery

Quick fix

GHSA-685w-vc84-wxcx — doorkeeper: upgrade to the fixed version with the command below.

bundle update doorkeeper

Details

Cross-site request forgery (CSRF) vulnerability in doorkeeper before 1.4.1 allows remote attackers to hijack the authentication of unspecified victims for requests that read a user OAuth authorization code via unknown vectors.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/doorkeeper
Introduced in: 0Fixed in: 1.4.1
Fixbundle update doorkeeper

References