CVE-2016-6582
Doorkeeper is vulnerable to replay attacks
9.1
CRITICAL
CVSS 3.1
EPSS 4.7%
Description
The Doorkeeper gem before 4.2.0 for Ruby might allow remote attackers to conduct replay attacks or revoke arbitrary tokens by leveraging failure to implement the OAuth 2.0 Token Revocation specification.
How to fix CVE-2016-6582
To remediate CVE-2016-6582, upgrade the affected package to a fixed version below.
- Debian/ruby-doorkeeper—upgrade to 4.2.0-3 or later
- —upgrade to 4.2.0 or later
Is CVE-2016-6582 being exploited?
Low — EPSS is 4.7%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 4.2.0-3
- from 0, < 4.2.0
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.1 | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H |