CVE-2023-34246

MEDIUM

Doorkeeper < 5.6.6 - Improper Authentication via Public Client Auto-Approval

Title source: llm
STIX 2.1

Description

Doorkeeper is an OAuth 2 provider for Ruby on Rails / Grape. Prior to version 5.6.6, Doorkeeper automatically processes authorization requests without user consent for public clients that have been previous approved. Public clients are inherently vulnerable to impersonation, their identity cannot be assured. This issue is fixed in version 5.6.6.

Scores

CVSS v3 4.2
EPSS 0.0031
EPSS Percentile 54.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-287
Status published
Products (2)
doorkeeper_project/doorkeeper < 5.6.6
rubygems/doorkeeper 0 - 5.6.6RubyGems
Published Jun 12, 2023
Tracked Since Feb 18, 2026