VDB
Sign up
MEDIUM6.1

GHSA-vv4c-g6q7-p3q7

Doorkeeper-openid_connect contains Open Redirect

Quick fix

GHSA-vv4c-g6q7-p3q7 — doorkeeper-openid_connect: upgrade to the fixed version with the command below.

bundle update doorkeeper-openid_connect

Details

Doorkeeper::OpenidConnect (aka the OpenID Connect extension for Doorkeeper) 1.4.x and 1.5.x before 1.5.4 has an open redirect via the redirect_uri field in an OAuth authorization request (that results in an error response) with the 'openid' scope and a prompt=none value. This allows phishing attacks against the authorization flow.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/doorkeeper-openid_connect
Introduced in: 1.4.0Fixed in: 1.5.4
Fixbundle update doorkeeper-openid_connect

References