CVE-2018-1000211
published 2018-07-13CVE-2018-1000211: Doorkeeper version 4.2.0 and later contains a Incorrect Access Control vulnerability in Token revocation API's authorized method that can result in Access…
PriorityP342high7.5CVSS 3.0
AVNACLPRNUINSUCHINAN
EPSS
1.61%
73.2th percentile
Doorkeeper version 4.2.0 and later contains a Incorrect Access Control vulnerability in Token revocation API's authorized method that can result in Access tokens are not revoked for public OAuth apps, leaking access until expiry.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ruby-doorkeeper | < ruby-doorkeeper 4.4.2-1 (bookworm) | ruby-doorkeeper 4.4.2-1 (bookworm) |
| doorkeeper_project | doorkeeper | <= 4.2.0 | — |
| doorkeeper_project | doorkeeper | >= 4.2.0 < 4.4.0 | 4.4.0 |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv7.5HIGH
vendor_debian7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Doorkeeper subject to Incorrect Permission Assignment
osv·2018-08-13
CVE-2018-1000211 [HIGH] Doorkeeper subject to Incorrect Permission Assignment
Doorkeeper subject to Incorrect Permission Assignment
Doorkeeper version 4.2.0 and later contains a Incorrect Access Control vulnerability in Token revocation API's authorized method that can result in Access tokens are not revoked for public OAuth apps, leaking access until expiry.
GHSA
Doorkeeper subject to Incorrect Permission Assignment
ghsa·2018-08-13
CVE-2018-1000211 [HIGH] CWE-732 Doorkeeper subject to Incorrect Permission Assignment
Doorkeeper subject to Incorrect Permission Assignment
Doorkeeper version 4.2.0 and later contains a Incorrect Access Control vulnerability in Token revocation API's authorized method that can result in Access tokens are not revoked for public OAuth apps, leaking access until expiry.
OSV
CVE-2018-1000211: Doorkeeper version 4
osv·2018-07-13·CVSS 7.5
CVE-2018-1000211 [HIGH] CVE-2018-1000211: Doorkeeper version 4
Doorkeeper version 4.2.0 and later contains a Incorrect Access Control vulnerability in Token revocation API's authorized method that can result in Access tokens are not revoked for public OAuth apps, leaking access until expiry.
Debian
CVE-2018-1000211: ruby-doorkeeper - Doorkeeper version 4.2.0 and later contains a Incorrect Access Control vulnerabi...
vendor_debian·2018·CVSS 7.5
CVE-2018-1000211 [HIGH] CVE-2018-1000211: ruby-doorkeeper - Doorkeeper version 4.2.0 and later contains a Incorrect Access Control vulnerabi...
Doorkeeper version 4.2.0 and later contains a Incorrect Access Control vulnerability in Token revocation API's authorized method that can result in Access tokens are not revoked for public OAuth apps, leaking access until expiry.
Scope: local
bookworm: resolved (fixed in 4.4.2-1)
bullseye: resolved (fixed in 4.4.2-1)
forky: resolved (fixed in 4.4.2-1)
sid: resolved (fixed in 4.4.2-1)
trixie: resolved (fixed in 4.4.2-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2018-07-13
Published