doorkeeper is vulnerable to Improper Authorization
65
Medium Risk
Doorkeeper's OAuth token revocation endpoint does not properly authorize revocation requests from public, non-confidential clients. A public client can submit a revocation request that revokes an access or refresh token it does not own. This breaks token isolation between public clients and can disrupt other clients' active sessions. The fix enforces proper client authorization on the revocation flow per RFC 7009 so a public client can only revoke its own tokens.
You are affected if you are using a version that falls within the vulnerable range and your Doorkeeper provider issues tokens to public (non-confidential) clients.
doorkeeper is vulnerable to Improper Authorization in versions 0.0.1 - 5.9.0.
Upgrade the doorkeeper library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant