ZeroHour

CVE-2018-1000211

CVSS 3.0
7.5 high
EPSS
2%p74
Published
()
Modified
Description

Doorkeeper version 4.2.0 and later contains a Incorrect Access Control vulnerability in Token revocation API's authorized method that can result in Access tokens are not revoked for public OAuth apps, leaking access until expiry.

Vendors
doorkeeper project
Products
doorkeeper
Weakness
CWE-732
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.