CVE-2018-1000088
published 2018-03-13CVE-2018-1000088: Doorkeeper version 2.1.0 through 4.2.5 contains a Cross Site Scripting (XSS) vulnerability in web view's OAuth app form, user authorization prompt web view…
PriorityP426medium6.1CVSS 3.0
AVNACLPRNUIRSCCLILAN
EPSS
1.48%
71.0th percentile
Doorkeeper version 2.1.0 through 4.2.5 contains a Cross Site Scripting (XSS) vulnerability in web view's OAuth app form, user authorization prompt web view that can result in Stored XSS on the OAuth Client's name will cause users interacting with it will execute payload. This attack appear to be exploitable via The victim must be tricked to click an opaque link to the web view that runs the XSS payload. A malicious version virtually indistinguishable from a normal link.. This vulnerability appears to have been fixed in 4.2.6, 4.3.0.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ruby-doorkeeper | < ruby-doorkeeper 4.3.1-1 (bookworm) | ruby-doorkeeper 4.3.1-1 (bookworm) |
| doorkeeper_project | doorkeeper | >= 2.1.0 < 4.2.6 | 4.2.6 |
| doorkeeper_project | doorkeeper | 2.1.0 – 4.2.5 | — |
CVSS provenance
nvdv3.06.1MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv9.1CRITICAL
vendor_ubuntu9.1CRITICAL
vendor_debian6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Doorkeeper vulnerabilities
vendor_ubuntu·2025-03-31·CVSS 9.1
CVE-2016-6582 [CRITICAL] Doorkeeper vulnerabilities
Title: Doorkeeper vulnerabilities
Summary: Several security issues were fixed in ruby-doorkeeper.
Jonathan Clem and Justin Bull discovered that Doorkeeper could allow
arbitrary token revocation and replay attacks. An attacker could possibly
use this issue to gain unauthorized access to a system. (CVE-2016-6582)
It was discovered that Doorkeeper incorrectly handled storing client names.
An attacker could possibly use this issue to execute a cross-site
scripting (XSS) attack. (CVE-2018-1000088)
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2018-1000088: ruby-doorkeeper - Doorkeeper version 2.1.0 through 4.2.5 contains a Cross Site Scripting (XSS) vul...
vendor_debian·2018·CVSS 6.1
CVE-2018-1000088 [MEDIUM] CVE-2018-1000088: ruby-doorkeeper - Doorkeeper version 2.1.0 through 4.2.5 contains a Cross Site Scripting (XSS) vul...
Doorkeeper version 2.1.0 through 4.2.5 contains a Cross Site Scripting (XSS) vulnerability in web view's OAuth app form, user authorization prompt web view that can result in Stored XSS on the OAuth Client's name will cause users interacting with it will execute payload. This attack appear to be exploitable via The victim must be tricked to click an opaque link to the web view that runs the XSS payload. A malicious version virtually indistinguishable from a normal link.. This vulnerability appears to have been fixed in 4.2.6, 4.3.0.
Scope: local
bookworm: resolved (fixed in 4.3.1-1)
bullseye: resolved (fixed in 4.3.1-1)
forky: resolved (fixed in 4.3.1-1)
sid: resolved (fixed in 4.3.1-1)
trixie: resolved (fixed in 4.3.1-1)
OSV
ruby-doorkeeper vulnerabilities
osv·2025-03-31·CVSS 9.1
CVE-2016-6582 [CRITICAL] ruby-doorkeeper vulnerabilities
ruby-doorkeeper vulnerabilities
Jonathan Clem and Justin Bull discovered that Doorkeeper could allow
arbitrary token revocation and replay attacks. An attacker could possibly
use this issue to gain unauthorized access to a system. (CVE-2016-6582)
It was discovered that Doorkeeper incorrectly handled storing client names.
An attacker could possibly use this issue to execute a cross-site
scripting (XSS) attack. (CVE-2018-1000088)
GHSA
Doorkeeper is vulnerable to stored XSS and code execution
ghsa·2018-03-13
CVE-2018-1000088 [MEDIUM] CWE-79 Doorkeeper is vulnerable to stored XSS and code execution
Doorkeeper is vulnerable to stored XSS and code execution
Doorkeeper version 2.1.0 through 4.2.5 contains a Cross Site Scripting (XSS) vulnerability in web view's OAuth app form, user authorization prompt web view that can result in Stored XSS on the OAuth Client's name will cause users interacting with it will execute payload. This attack appear to be exploitable via The victim must be tricked to click an opaque link to the web view that runs the XSS payload. A malicious version virtually indistinguishable from a normal link. This vulnerability appears to have been fixed in 4.2.6, 4.3.0.
OSV
Doorkeeper is vulnerable to stored XSS and code execution
osv·2018-03-13
CVE-2018-1000088 [MEDIUM] Doorkeeper is vulnerable to stored XSS and code execution
Doorkeeper is vulnerable to stored XSS and code execution
Doorkeeper version 2.1.0 through 4.2.5 contains a Cross Site Scripting (XSS) vulnerability in web view's OAuth app form, user authorization prompt web view that can result in Stored XSS on the OAuth Client's name will cause users interacting with it will execute payload. This attack appear to be exploitable via The victim must be tricked to click an opaque link to the web view that runs the XSS payload. A malicious version virtually indistinguishable from a normal link. This vulnerability appears to have been fixed in 4.2.6, 4.3.0.
OSV
CVE-2018-1000088: Doorkeeper version 2
osv·2018-03-13·CVSS 6.1
CVE-2018-1000088 [MEDIUM] CVE-2018-1000088: Doorkeeper version 2
Doorkeeper version 2.1.0 through 4.2.5 contains a Cross Site Scripting (XSS) vulnerability in web view's OAuth app form, user authorization prompt web view that can result in Stored XSS on the OAuth Client's name will cause users interacting with it will execute payload. This attack appear to be exploitable via The victim must be tricked to click an opaque link to the web view that runs the XSS payload. A malicious version virtually indistinguishable from a normal link.. This vulnerability appears to have been fixed in 4.2.6, 4.3.0.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/doorkeeper-gem/doorkeeper/issues/969https://github.com/doorkeeper-gem/doorkeeper/pull/970https://github.com/doorkeeper-gem/doorkeeper/releases/tag/v4.3.0https://github.com/rubysec/ruby-advisory-db/pull/328/fileshttps://github.com/doorkeeper-gem/doorkeeper/issues/969https://github.com/doorkeeper-gem/doorkeeper/pull/970https://github.com/doorkeeper-gem/doorkeeper/releases/tag/v4.3.0https://github.com/rubysec/ruby-advisory-db/pull/328/files
2018-03-13
Published