9.1 CVE-2016-6582

Patch
 

The Doorkeeper gem before 4.2.0 for Ruby might allow remote attackers to conduct replay attacks or revoke arbitrary tokens by leveraging failure to implement the OAuth 2.0 Token Revocation specification.
https://nvd.nist.gov/vuln/detail/CVE-2016-6582

Categories

CWE-254

References


 

CPE

cpe start end
Configuration 1
cpe:2.3:a:doorkeeper_project:doorkeeper:*:*:*:*:*:ruby:*:* <= 4.1.0


REMEDIATION


Patch

Url
http://seclists.org/fulldisclosure/2016/Aug/105
https://github.com/doorkeeper-gem/doorkeeper/issues/875
https://github.com/doorkeeper-gem/doorkeeper/releases/tag/v4.2.0
http://seclists.org/fulldisclosure/2016/Aug/105
https://github.com/doorkeeper-gem/doorkeeper/issues/875
https://github.com/doorkeeper-gem/doorkeeper/releases/tag/v4.2.0


EXPLOITS


Exploit-db.com

id description date
No known exploits

POC Github

Url
No known exploits

Other Nist (github, ...)

Url
No known exploits


CAPEC


Common Attack Pattern Enumerations and Classifications

id description severity
No entry