CVE-2018-1000211

Doorkeeper version 4.2.0 and later contains a Incorrect Access Control vulnerability in Token revocation API's authorized method that can result in Access tokens are not revoked for public OAuth apps, leaking access until expiry.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:doorkeeper_project:doorkeeper:*:*:*:*:*:*:*:*

Information

Published : 2018-07-13 11:29

Updated : 2019-10-02 17:03


NVD link : CVE-2018-1000211

Mitre link : CVE-2018-1000211


JSON object : View

CWE
CWE-732

Incorrect Permission Assignment for Critical Resource

Advertisement

dedicated server usa

Products Affected

doorkeeper_project

  • doorkeeper