[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249461

 
 

909

 
 

195508

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

CVE-2018-1000088 -- ruby-doorkeeper

ID: oval:org.secpod.oval:def:2001425Date: (C)2019-04-21   (M)2021-06-02
Class: VULNERABILITYFamily: unix




Doorkeeper version 2.1.0 through 4.2.5 contains a Cross Site Scripting vulnerability in web view"s OAuth app form, user authorization prompt web view that can result in Stored XSS on the OAuth Client"s name will cause users interacting with it will execute payload. This attack appear to be exploitable via The victim must be tricked to click an opaque link to the web view that runs the XSS payload. A malicious version virtually indistinguishable from a normal link.. This vulnerability appears to have been fixed in 4.2.6, 4.3.0.

Platform:
Debian 9.x
Product:
ruby-doorkeeper
Reference:
CVE-2018-1000088
CVE    1
CVE-2018-1000088
CPE    2
cpe:/a:github:ruby-doorkeeper
cpe:/o:debian:debian_linux:9.x

© SecPod Technologies