VDB
Sign up
HIGH7.5

GHSA-j7vx-8mqj-cqp9

Exposure of Sensitive Information to an Unauthorized Actor in Doorkeeper

Quick fix

GHSA-j7vx-8mqj-cqp9 — doorkeeper: upgrade to the fixed version with the command below.

bundle update doorkeeper

Details

### Impact Information disclosure vulnerability. Allows an attacker to see all `Doorkeeper::Application` model attribute values (including secrets) using authorized applications controller if it's enabled (GET /oauth/authorized_applications.json).

### Patches

These versions have the fix:

* 5.0.3 * 5.1.1 * 5.2.5 * 5.3.2

### Workarounds Patch `Doorkeeper::Application` model `#as_json(options = {})` method and define only those attributes you want to expose.

Additional recommended hardening is to enable application secrets hashing ([guide](https://doorkeeper.gitbook.io/guides/security/token-and-application-secrets)), available since Doorkeeper 5.1. This would render the exposed secret useless.

### References

- Commit with fix: https://github.com/doorkeeper-gem/doorkeeper/commit/25d038022c2fcad45af5b73f9d003cf38ff491f6 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10187

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/doorkeeper
Introduced in: 5.0.0Fixed in: 5.0.3
Fixbundle update doorkeeper
RubyGems/doorkeeper
Introduced in: 5.1.0Fixed in: 5.1.1
Fixbundle update doorkeeper
RubyGems/doorkeeper
Introduced in: 5.2.0Fixed in: 5.2.5
Fixbundle update doorkeeper
RubyGems/doorkeeper
Introduced in: 5.3.0Fixed in: 5.3.2
Fixbundle update doorkeeper

References