[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250770

 
 

909

 
 

196157

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

CVE-2018-1000211 -- ruby-doorkeeper

ID: oval:org.secpod.oval:def:2000842Date: (C)2019-04-22   (M)2021-06-02
Class: VULNERABILITYFamily: unix




Doorkeeper version 4.2.0 and later contains a Incorrect Access Control vulnerability in Token revocation API"s authorized method that can result in Access tokens are not revoked for public OAuth apps, leaking access until expiry.

Platform:
Debian 9.x
Product:
ruby-doorkeeper
Reference:
CVE-2018-1000211
CVE    1
CVE-2018-1000211
CPE    2
cpe:/a:github:ruby-doorkeeper
cpe:/o:debian:debian_linux:9.x

© SecPod Technologies