CVE-2018-1000211
Doorkeeper version 4.2.0 and later contains a Incorrect Access Control vulnerability in Token revocation API's authorized method that can result in Access tokens are not revoked for public OAuth apps, leaking access until expiry.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.61%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Doorkeeper version 4.2.0 and later contains a Incorrect Access Control vulnerability in Token revocation API's authorized method that can result in Access tokens are not revoked for public OAuth apps, leaking access until expiry.
- CVSS 3.0
- 7.5 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 1.61% probability · 75th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-732
- Affected
- doorkeeper project/doorkeeper
- Source
- cve@mitre.org
References
- https://github.com/doorkeeper-gem/doorkeeper/issues/891Third Party Advisory
- https://github.com/doorkeeper-gem/doorkeeper/pull/1119Third Party Advisory
- https://github.com/doorkeeper-gem/doorkeeper/issues/891Third Party Advisory
- https://github.com/doorkeeper-gem/doorkeeper/pull/1119Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.