CVE-2023-34246
Last modified
CVE-2023-34246 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. Doorkeeper is an OAuth 2 provider for Ruby on Rails / Grape. Prior to version 5.6.6, Doorkeeper automatically processes authorization requests without user consent for public clients that have been previous approved. EPSS estimates a 0.72% chance of exploitation in the next 30 days.
Description
Doorkeeper is an OAuth 2 provider for Ruby on Rails / Grape. Prior to version 5.6.6, Doorkeeper automatically processes authorization requests without user consent for public clients that have been previous approved. Public clients are inherently vulnerable to impersonation, their identity cannot be assured. This issue is fixed in version 5.6.6.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Doorkeeper Project | Doorkeeper | < 5.6.6 |
References
- https://github.com/doorkeeper-gem/doorkeeper/issues/1589Exploit, Issue Tracking
- https://www.rfc-editor.org/rfc/rfc8252#section-8.6Technical Description
- https://github.com/doorkeeper-gem/doorkeeper/issues/1589Exploit, Issue Tracking
- https://www.rfc-editor.org/rfc/rfc8252#section-8.6Technical Description
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-34246?
How severe is CVE-2023-34246?
How do I fix CVE-2023-34246?
Are you affected by CVE-2023-34246?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
