Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Doorkeeper version 4.2.0 and later contains a Incorrect Access Control vulnerability in Token revocation API's authorized method that can result in Access tokens are not revoked for public OAuth apps, leaking access until expiry.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Doorkeepe 访问控制错误漏洞
Vulnerability Description
Doorkeeper是一款适用于Rails/Grape应用的OAuth 2身份验证提供程序。 Doorkeeper 4.2.0及之后版本中的Token revocation API的授权方法存在访问控制错误漏洞。远程攻击者可利用该漏洞获取系统的访问权限。
CVSS Information
N/A
Vulnerability Type
N/A