MEDIUMRubyGems →
Doorkeeper Improper Authentication vulnerability
Doorkeeper Improper Authentication vulnerability
Affected packages
- doorkeeper— before 5.6.6
Exploit signal
- Known exploited (CISA KEV)
- No
- EPSS score
- —
- EPSS percentile
- —
EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.
Sources
- https://github.com/doorkeeper-gem/doorkeeper/security/advisories/GHSA-7w2c-w47h-789w
- https://nvd.nist.gov/vuln/detail/CVE-2023-34246
- https://github.com/doorkeeper-gem/doorkeeper/issues/1589
- https://github.com/doorkeeper-gem/doorkeeper/pull/1646
- https://github.com/doorkeeper-gem/doorkeeper
- https://github.com/doorkeeper-gem/doorkeeper/releases/tag/v5.6.6
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/doorkeeper/CVE-2023-34246.yml
- https://lists.debian.org/debian-lts-announce/2023/07/msg00016.html
- https://lists.debian.org/debian-lts-announce/2024/12/msg00010.html
- https://www.rfc-editor.org/rfc/rfc8252#section-8.6
Structured record: https://osv.dev/vulnerability/GHSA-7w2c-w47h-789w
Recommended response stack
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.
Get incidents like this as alerts for your stack.
Join the beta