Known Vulnerabilities for products from Doorkeeper Project
Listed below are 6 of the newest known vulnerabilities associated with the vendor "Doorkeeper Project".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2023-34246 json | Doorkeeper is an OAuth 2 provider for Ruby on Rails / Grape. Prior to version 5.6.6, Doorkeeper automatically processes autho... | 6.5 - MEDIUM | 2023-06-12 | 2023-07-12 |
| CVE-2020-10187 json | Doorkeeper version 5.0.0 and later contains an information disclosure vulnerability that allows an attacker to retrieve the c... | 7.5 - HIGH | 2020-05-04 | 2021-07-21 |
| CVE-2018-1000211 json | Doorkeeper version 4.2.0 and later contains a Incorrect Access Control vulnerability in Token revocation API's authorized met... | 7.5 - HIGH | 2018-07-13 | 2019-10-03 |
| CVE-2018-1000088 json | Doorkeeper version 2.1.0 through 4.2.5 contains a Cross Site Scripting (XSS) vulnerability in web view's OAuth app form, user... | 6.1 - MEDIUM | 2018-03-13 | 2018-04-11 |
| CVE-2016-6582 json | The Doorkeeper gem before 4.2.0 for Ruby might allow remote attackers to conduct replay attacks or revoke arbitrary tokens by... | Not Provided | 2017-01-23 | 2025-04-20 |
| CVE-2014-8144 json | Cross-site request forgery (CSRF) vulnerability in doorkeeper before 1.4.1 allows remote attackers to hijack the authenticati... | Not Provided | 2014-12-31 | 2026-05-06 |
Known software with vulnerabilities from Doorkeeper Project
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Doorkeeper Project | Doorkeeper | 0.1.0 |