9.1
CVE-2016-6582
- EPSS 4.69%
- Veröffentlicht 23.01.2017 21:59:02
- Zuletzt bearbeitet 13.05.2026 00:24:29
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
The Doorkeeper gem before 4.2.0 for Ruby might allow remote attackers to conduct replay attacks or revoke arbitrary tokens by leveraging failure to implement the OAuth 2.0 Token Revocation specification.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Doorkeeper Project ≫ Doorkeeper SwPlatformruby Version <= 4.1.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 4.69% | 0.906 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.1 | 3.9 | 5.2 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
|
| nvd@nist.gov | 6.4 | 10 | 4.9 |
AV:N/AC:L/Au:N/C:N/I:P/A:P
|
http://packetstormsecurity.com/files/138430/Doorkeeper-4.1.0-Token-Revocation.html
http://seclists.org/fulldisclosure/2016/Aug/105
http://www.securityfocus.com/archive/1/539268/100/0/threaded
http://www.securityfocus.com/bid/92551
https://github.com/doorkeeper-gem/doorkeeper/issues/875
https://github.com/doorkeeper-gem/doorkeeper/releases/tag/v4.2.0