9.1
CVE-2016-6582
- EPSS 4.72%
- Veröffentlicht 23.01.2017 21:59:02
- Zuletzt bearbeitet 13.05.2026 00:24:29
- Erkennungen
The Doorkeeper gem before 4.2.0 for Ruby might allow remote attackers to conduct replay attacks or revoke arbitrary tokens by leveraging failure to implement the OAuth 2.0 Token Revocation specification.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Doorkeeper Project ≫ Doorkeeper SwPlatform ruby Version <= 4.1.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 4.72% | 0.908 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 9.1 | 3.9 | 5.2 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
|
| NIST | 6.4 | 10 | 4.9 |
AV:N/AC:L/Au:N/C:N/I:P/A:P
|
http://packetstormsecurity.com/files/138430/Doorkeeper-4.1.0-Token-Revocation.html
http://seclists.org/fulldisclosure/2016/Aug/105
http://www.securityfocus.com/archive/1/539268/100/0/threaded
http://www.securityfocus.com/bid/92551
https://github.com/doorkeeper-gem/doorkeeper/issues/875
https://github.com/doorkeeper-gem/doorkeeper/releases/tag/v4.2.0