Description
Cross-site request forgery (CSRF) vulnerability in doorkeeper before 1.4.1 allows remote attackers to hijack the authentication of unspecified victims for requests that read a user OAuth authorization code via unknown vectors.
References (3)
Core 3
Core References
Various Sources x_refsource_confirm
https://github.com/doorkeeper-gem/doorkeeper/blob/master/CHANGELOG.md
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/99342
Mailing List mailing-list
x_refsource_mlist
http://seclists.org/oss-sec/2014/q4/1076
Scores
EPSS
0.0013
EPSS Percentile
31.3%
Details
CWE
CWE-352
Status
published
Products (2)
doorkeeper_project/doorkeeper
< 1.4.0
rubygems/doorkeeper
0 - 1.4.1RubyGems
Published
Dec 31, 2014
Tracked Since
Feb 18, 2026