The Doorkeeper gem before 4.2.0 for Ruby might allow remote attackers to conduct replay attacks or revoke arbitrary tokens by leveraging failure to implement the OAuth 2.0 Token Revocation specification.
Software security is not security software. Here we're concerned with topics like authentication, access control, confidentiality, cryptography, and privilege management.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/92551 | vdb entry third party advisory |
http://packetstormsecurity.com/files/138430/Doorkeeper-4.1.0-Token-Revocation.html | vdb entry third party advisory |
http://www.securityfocus.com/archive/1/539268/100/0/threaded | mailing list |
http://seclists.org/fulldisclosure/2016/Aug/105 | mailing list third party advisory patch |
https://github.com/doorkeeper-gem/doorkeeper/releases/tag/v4.2.0 | issue tracking release notes patch third party advisory |
https://github.com/doorkeeper-gem/doorkeeper/issues/875 | issue tracking third party advisory patch |