CVE-2016-6582
published 2017-01-23CVE-2016-6582: The Doorkeeper gem before 4.2.0 for Ruby might allow remote attackers to conduct replay attacks or revoke arbitrary tokens by leveraging failure to implement…
PriorityP351critical9.1CVSS 3.0
AVNACLPRNUINSUCNIHAH
EPSS
4.72%
90.8th percentile
The Doorkeeper gem before 4.2.0 for Ruby might allow remote attackers to conduct replay attacks or revoke arbitrary tokens by leveraging failure to implement the OAuth 2.0 Token Revocation specification.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ruby-doorkeeper | < ruby-doorkeeper 4.2.0-3 (bookworm) | ruby-doorkeeper 4.2.0-3 (bookworm) |
| doorkeeper_project | doorkeeper | <= 4.1.0 | — |
| doorkeeper_project | doorkeeper | >= 0 < 4.2.0 | 4.2.0 |
CVSS provenance
nvdv3.09.1CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:P
osv9.1CRITICAL
vendor_debian9.1CRITICAL
vendor_ubuntu9.1CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Doorkeeper vulnerabilities
vendor_ubuntu·2025-03-31·CVSS 9.1
CVE-2016-6582 [CRITICAL] Doorkeeper vulnerabilities
Title: Doorkeeper vulnerabilities
Summary: Several security issues were fixed in ruby-doorkeeper.
Jonathan Clem and Justin Bull discovered that Doorkeeper could allow
arbitrary token revocation and replay attacks. An attacker could possibly
use this issue to gain unauthorized access to a system. (CVE-2016-6582)
It was discovered that Doorkeeper incorrectly handled storing client names.
An attacker could possibly use this issue to execute a cross-site
scripting (XSS) attack. (CVE-2018-1000088)
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2016-6582: ruby-doorkeeper - The Doorkeeper gem before 4.2.0 for Ruby might allow remote attackers to conduct...
vendor_debian·2016·CVSS 9.1
CVE-2016-6582 [CRITICAL] CVE-2016-6582: ruby-doorkeeper - The Doorkeeper gem before 4.2.0 for Ruby might allow remote attackers to conduct...
The Doorkeeper gem before 4.2.0 for Ruby might allow remote attackers to conduct replay attacks or revoke arbitrary tokens by leveraging failure to implement the OAuth 2.0 Token Revocation specification.
Scope: local
bookworm: resolved (fixed in 4.2.0-3)
bullseye: resolved (fixed in 4.2.0-3)
forky: resolved (fixed in 4.2.0-3)
sid: resolved (fixed in 4.2.0-3)
trixie: resolved (fixed in 4.2.0-3)
OSV
ruby-doorkeeper vulnerabilities
osv·2025-03-31·CVSS 9.1
CVE-2016-6582 [CRITICAL] ruby-doorkeeper vulnerabilities
ruby-doorkeeper vulnerabilities
Jonathan Clem and Justin Bull discovered that Doorkeeper could allow
arbitrary token revocation and replay attacks. An attacker could possibly
use this issue to gain unauthorized access to a system. (CVE-2016-6582)
It was discovered that Doorkeeper incorrectly handled storing client names.
An attacker could possibly use this issue to execute a cross-site
scripting (XSS) attack. (CVE-2018-1000088)
OSV
Doorkeeper is vulnerable to replay attacks
osv·2017-10-24
CVE-2016-6582 [CRITICAL] Doorkeeper is vulnerable to replay attacks
Doorkeeper is vulnerable to replay attacks
The Doorkeeper gem before 4.2.0 for Ruby might allow remote attackers to conduct replay attacks or revoke arbitrary tokens by leveraging failure to implement the OAuth 2.0 Token Revocation specification.
GHSA
Doorkeeper is vulnerable to replay attacks
ghsa·2017-10-24
CVE-2016-6582 [CRITICAL] CWE-1254 Doorkeeper is vulnerable to replay attacks
Doorkeeper is vulnerable to replay attacks
The Doorkeeper gem before 4.2.0 for Ruby might allow remote attackers to conduct replay attacks or revoke arbitrary tokens by leveraging failure to implement the OAuth 2.0 Token Revocation specification.
OSV
CVE-2016-6582: The Doorkeeper gem before 4
osv·2017-01-23·CVSS 9.1
CVE-2016-6582 [CRITICAL] CVE-2016-6582: The Doorkeeper gem before 4
The Doorkeeper gem before 4.2.0 for Ruby might allow remote attackers to conduct replay attacks or revoke arbitrary tokens by leveraging failure to implement the OAuth 2.0 Token Revocation specification.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://packetstormsecurity.com/files/138430/Doorkeeper-4.1.0-Token-Revocation.htmlhttp://seclists.org/fulldisclosure/2016/Aug/105http://www.securityfocus.com/archive/1/539268/100/0/threadedhttp://www.securityfocus.com/bid/92551https://github.com/doorkeeper-gem/doorkeeper/issues/875https://github.com/doorkeeper-gem/doorkeeper/releases/tag/v4.2.0http://packetstormsecurity.com/files/138430/Doorkeeper-4.1.0-Token-Revocation.htmlhttp://seclists.org/fulldisclosure/2016/Aug/105http://www.securityfocus.com/archive/1/539268/100/0/threadedhttp://www.securityfocus.com/bid/92551https://github.com/doorkeeper-gem/doorkeeper/issues/875https://github.com/doorkeeper-gem/doorkeeper/releases/tag/v4.2.0
2017-01-23
Published