CVE-2016-6582

The Doorkeeper gem before 4.2.0 for Ruby might allow remote attackers to conduct replay attacks or revoke arbitrary tokens by leveraging failure to implement the OAuth 2.0 Token Revocation specification.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:doorkeeper_project:doorkeeper:*:*:*:*:*:ruby:*:*

History

No history.

Information

Published : 2017-01-23 21:59

Updated : 2024-02-04 19:11


NVD link : CVE-2016-6582

Mitre link : CVE-2016-6582

CVE.ORG link : CVE-2016-6582


JSON object : View

Products Affected

doorkeeper_project

  • doorkeeper
CWE
CWE-254

7PK - Security Features