ZeroHour

CVE-2016-6582

CVSS 3.0
9.1 critical
EPSS
5%p91
Published
()
Modified
Description

The Doorkeeper gem before 4.2.0 for Ruby might allow remote attackers to conduct replay attacks or revoke arbitrary tokens by leveraging failure to implement the OAuth 2.0 Token Revocation specification.

Vendors
doorkeeper project
Products
doorkeeper
Weakness
CWE-254
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

In the news

No ingested article mentions this CVE yet.