CVE-2018-1000211
Doorkeeper subject to Incorrect Permission Assignment
7.5
HIGH
CVSS 3.1
EPSS 1.6%
Description
Doorkeeper version 4.2.0 and later contains a Incorrect Access Control vulnerability in Token revocation API's authorized method that can result in Access tokens are not revoked for public OAuth apps, leaking access until expiry.
How to fix CVE-2018-1000211
To remediate CVE-2018-1000211, upgrade the affected package to a fixed version below.
- Debian/ruby-doorkeeper—upgrade to 4.4.2-1 or later
- —upgrade to 4.4.0 or later
Is CVE-2018-1000211 being exploited?
Low — EPSS is 1.6%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 4.4.2-1
- >= 4.2.0, < 4.4.0
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |