Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2023-34246
Description:Doorkeeper is an OAuth 2 provider for Ruby on Rails / Grape. Prior to version 5.6.6, Doorkeeper automatically processes authorization requests without user consent for public clients that have been previous approved. Public clients are inherently vulnerable to impersonation, their identity cannot be assured. This issue is fixed in version 5.6.6.
Test IDs: 1.3.6.1.4.1.25623.1.1.1.2.2024.3989   1.3.6.1.4.1.25623.1.1.12.2023.6210.1   1.3.6.1.4.1.25623.1.1.1.2.2023.3494  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2023-34246
https://github.com/doorkeeper-gem/doorkeeper/issues/1589
https://github.com/doorkeeper-gem/doorkeeper/issues/1589
https://github.com/doorkeeper-gem/doorkeeper/pull/1646
https://github.com/doorkeeper-gem/doorkeeper/pull/1646
https://github.com/doorkeeper-gem/doorkeeper/releases/tag/v5.6.6
https://github.com/doorkeeper-gem/doorkeeper/releases/tag/v5.6.6
https://github.com/doorkeeper-gem/doorkeeper/security/advisories/GHSA-7w2c-w47h-789w
https://github.com/doorkeeper-gem/doorkeeper/security/advisories/GHSA-7w2c-w47h-789w
https://www.rfc-editor.org/rfc/rfc8252#section-8.6
https://www.rfc-editor.org/rfc/rfc8252#section-8.6
https://lists.debian.org/debian-lts-announce/2023/07/msg00016.html




© 1998-2025 E-Soft Inc. All rights reserved.