CVE-2016-6582

critical
Published 2016-08-18 · Modified 2024-02-16
CVSS v3
9.1
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
CVSS v2
6.4
VIR risk
9.1

Description

The Doorkeeper gem before 4.2.0 for Ruby might allow remote attackers to conduct replay attacks or revoke arbitrary tokens by leveraging failure to implement the OAuth 2.0 Token Revocation specification.

Predictions

Exploit likelihood
94%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2016-6582

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://github.com/doorkeeper-gem/doorkeeper/releases/tag/v4.2.0

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://github.com/doorkeeper-gem/doorkeeper/issues/875

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — http://seclists.org/fulldisclosure/2016/Aug/105

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed4.2.0-3
debian debianbullseyefixed4.2.0-3
debian debianforkyfixed4.2.0-3
debian debiansidfixed4.2.0-3
debian debiantrixiefixed4.2.0-3

Package impact

EcosystemPackageVulnerableFixed
ruby RubyGemsdoorkeeper!< 1.2.0||<>= 4.2.0>= 4.2.0
ruby RubyGemsdoorkeeper<4.2.04.2.0

Application impact

VendorProductVersionsFixed
doorkeeper_projectdoorkeeper{"endIncluding":"4.1.0"}

References

CWEs

CWE-254

Verify integrity in audit chain (admin only). AS-IS.