GHSA-j7vx-8mqj-cqp9
Exposure of Sensitive Information to an Unauthorized Actor in Doorkeeper
Quick fix
GHSA-j7vx-8mqj-cqp9 — doorkeeper: upgrade to the fixed version with the command below.
bundle update doorkeeperDetails
### Impact Information disclosure vulnerability. Allows an attacker to see all `Doorkeeper::Application` model attribute values (including secrets) using authorized applications controller if it's enabled (GET /oauth/authorized_applications.json).
### Patches
These versions have the fix:
* 5.0.3 * 5.1.1 * 5.2.5 * 5.3.2
### Workarounds Patch `Doorkeeper::Application` model `#as_json(options = {})` method and define only those attributes you want to expose.
Additional recommended hardening is to enable application secrets hashing ([guide](https://doorkeeper.gitbook.io/guides/security/token-and-application-secrets)), available since Doorkeeper 5.1. This would render the exposed secret useless.
### References
- Commit with fix: https://github.com/doorkeeper-gem/doorkeeper/commit/25d038022c2fcad45af5b73f9d003cf38ff491f6 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10187
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/doorkeeper-gem/doorkeeper/security/advisories/GHSA-j7vx-8mqj-cqp9[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2020-10187[ADVISORY]
- https://github.com/rubysec/ruby-advisory-db/pull/446[WEB]
- https://github.com/doorkeeper-gem/doorkeeper/commit/25d038022c2fcad45af5b73f9d003cf38ff491f6[WEB]
- https://github.com/doorkeeper-gem/doorkeeper/releases[WEB]
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/doorkeeper/CVE-2020-10187.yml[WEB]