CVE-2016-6582
—CVSS 3.0
9.1 critical
EPSS
5%p91
Published
()
Modified
Description
The Doorkeeper gem before 4.2.0 for Ruby might allow remote attackers to conduct replay attacks or revoke arbitrary tokens by leveraging failure to implement the OAuth 2.0 Token Revocation specification.
- Vendors
- doorkeeper project
- Products
- doorkeeper
- Weakness
- CWE-254
- Vector
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.