HIGHRubyGems →
Exposure of Sensitive Information to an Unauthorized Actor in Doorkeeper
Exposure of Sensitive Information to an Unauthorized Actor in Doorkeeper
Affected packages
- doorkeeper— 5.0.0 → 5.0.3
Exploit signal
- Known exploited (CISA KEV)
- No
- EPSS score
- —
- EPSS percentile
- —
EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.
Sources
- https://github.com/doorkeeper-gem/doorkeeper/security/advisories/GHSA-j7vx-8mqj-cqp9
- https://nvd.nist.gov/vuln/detail/CVE-2020-10187
- https://github.com/rubysec/ruby-advisory-db/pull/446
- https://github.com/doorkeeper-gem/doorkeeper/commit/25d038022c2fcad45af5b73f9d003cf38ff491f6
- https://github.com/doorkeeper-gem/doorkeeper/releases
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/doorkeeper/CVE-2020-10187.yml
Structured record: https://osv.dev/vulnerability/GHSA-j7vx-8mqj-cqp9
Recommended response stack
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.
Get incidents like this as alerts for your stack.
Join the beta