CVE-2023-34246
MEDIUMDoorkeeper < 5.6.6 - Improper Authentication via Public Client Auto-Approval
Title source: llmDescription
Doorkeeper is an OAuth 2 provider for Ruby on Rails / Grape. Prior to version 5.6.6, Doorkeeper automatically processes authorization requests without user consent for public clients that have been previous approved. Public clients are inherently vulnerable to impersonation, their identity cannot be assured. This issue is fixed in version 5.6.6.
References (7)
Core 7
Core References
Vendor Advisory x_refsource_confirm
https://github.com/doorkeeper-gem/doorkeeper/security/advisories/GHSA-7w2c-w47h-789w
Exploit, Issue Tracking x_refsource_misc
https://github.com/doorkeeper-gem/doorkeeper/issues/1589
Patch x_refsource_misc
https://github.com/doorkeeper-gem/doorkeeper/pull/1646
Release Notes x_refsource_misc
https://github.com/doorkeeper-gem/doorkeeper/releases/tag/v5.6.6
Technical Description x_refsource_misc
https://www.rfc-editor.org/rfc/rfc8252#section-8.6
Scores
CVSS v3
4.2
EPSS
0.0031
EPSS Percentile
54.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
total
Details
CWE
CWE-287
Status
published
Products (2)
doorkeeper_project/doorkeeper
< 5.6.6
rubygems/doorkeeper
0 - 5.6.6RubyGems
Published
Jun 12, 2023
Tracked Since
Feb 18, 2026