doorkeeper
Doorkeeper is an OAuth 2 provider for Ruby on Rails / Grape.
Activity
- Latest release
- 4d ago
- Total releases
- 133
- Cadence
- ~35 days
- Last 12 months
- 10
Reach
- Stars
- 5.5k
Details
- License
- MIT
- First release
- Nov 28, 2011
| Version | Released | |
|---|---|---|
5.9.7
patch
|
5.9.7
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
6.0.0.rc1
pre
|
6.0.0.rc1
pre
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
5.9.6
patch
|
5.9.6
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
6.0.0.beta2
pre
|
6.0.0.beta2
pre
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
5.9.5
patch
|
5.9.5
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
6.0.0.beta1
pre
|
6.0.0.beta1
pre
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
5.9.3
patch
|
5.9.3
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
5.9.2
patch
|
5.9.2
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
5.9.1
patch
|
5.9.1
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
5.9.0
minor
|
5.9.0
minor
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
5.8.2
patch
|
5.8.2
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
5.8.1
patch
|
5.8.1
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
5.8.0
minor
|
5.8.0
minor
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
5.7.1
patch
|
5.7.1
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
5.7.0
minor
|
5.7.0
minor
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
5.6.9
patch
|
5.6.9
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
5.6.8
patch
|
5.6.8
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
5.6.7
patch
|
5.6.7
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
5.6.6
patch
|
5.6.6
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
5.6.5
patch
1 CVE
CVE-2023-34246
GHSA-7w2c-w47h-789w
Jun 12, 2023
Doorkeeper Improper Authentication vulnerability
4.2
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
None
OAuth RFC 8252 says https://www.rfc-editor.org/rfc/rfc8252#section-8.6
But Doorkeeper automatically processes authorization requests without user consent for public clients that have been previously approved. Public clients are inherently vulnerable to impersonation, their identity cannot be assured. Issue https://github.com/doorkeeper-gem/doorkeeper/issues/1589 Fix https://github.com/doorkeeper-gem/doorkeeper/pull/1646 Affected versions
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
+ 102 more Show less
0.5.0.rc1
0.6.0
0.6.0.rc1
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
1.0.0
1.0.0.rc1
1.0.0.rc2
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
2.0.0
2.0.0.alpha1
2.0.0.rc2
2.0.0.rc3
2.0.1
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
3.0.0
3.0.0.rc1
3.0.0.rc2
3.0.1
3.1.0
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.0.rc3
4.0.0.rc4
4.1.0
4.2.0
4.2.5
4.2.6
4.3.0
4.3.1
4.3.2
4.4.0
4.4.1
4.4.2
4.4.3
5.0.0
5.0.0.rc1
5.0.0.rc2
5.0.1
5.0.2
5.0.3
5.1.0
5.1.0.rc1
5.1.0.rc2
5.1.1
5.1.2
5.2.0
5.2.0.rc1
5.2.0.rc2
5.2.0.rc3
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.3.0
5.3.1
5.3.2
5.3.3
5.4.0
5.4.0.rc1
5.4.0.rc2
5.5.0
5.5.0.rc1
5.5.0.rc2
5.5.1
5.5.2
5.5.3
5.5.4
5.6.0
5.6.0.rc1
5.6.0.rc2
5.6.1
5.6.2
5.6.3
5.6.4
5.6.5
Fixed in
5.6.6
References
Updated Sep 10, 2026 · Source: OSV.dev |
5.6.5
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
5.6.4
patch
1 CVE
CVE-2023-34246
GHSA-7w2c-w47h-789w
Jun 12, 2023
Doorkeeper Improper Authentication vulnerability
4.2
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
None
OAuth RFC 8252 says https://www.rfc-editor.org/rfc/rfc8252#section-8.6
But Doorkeeper automatically processes authorization requests without user consent for public clients that have been previously approved. Public clients are inherently vulnerable to impersonation, their identity cannot be assured. Issue https://github.com/doorkeeper-gem/doorkeeper/issues/1589 Fix https://github.com/doorkeeper-gem/doorkeeper/pull/1646 Affected versions
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
+ 102 more Show less
0.5.0.rc1
0.6.0
0.6.0.rc1
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
1.0.0
1.0.0.rc1
1.0.0.rc2
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
2.0.0
2.0.0.alpha1
2.0.0.rc2
2.0.0.rc3
2.0.1
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
3.0.0
3.0.0.rc1
3.0.0.rc2
3.0.1
3.1.0
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.0.rc3
4.0.0.rc4
4.1.0
4.2.0
4.2.5
4.2.6
4.3.0
4.3.1
4.3.2
4.4.0
4.4.1
4.4.2
4.4.3
5.0.0
5.0.0.rc1
5.0.0.rc2
5.0.1
5.0.2
5.0.3
5.1.0
5.1.0.rc1
5.1.0.rc2
5.1.1
5.1.2
5.2.0
5.2.0.rc1
5.2.0.rc2
5.2.0.rc3
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.3.0
5.3.1
5.3.2
5.3.3
5.4.0
5.4.0.rc1
5.4.0.rc2
5.5.0
5.5.0.rc1
5.5.0.rc2
5.5.1
5.5.2
5.5.3
5.5.4
5.6.0
5.6.0.rc1
5.6.0.rc2
5.6.1
5.6.2
5.6.3
5.6.4
5.6.5
Fixed in
5.6.6
References
Updated Sep 10, 2026 · Source: OSV.dev |
5.6.4
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
5.6.3
patch
1 CVE
CVE-2023-34246
GHSA-7w2c-w47h-789w
Jun 12, 2023
Doorkeeper Improper Authentication vulnerability
4.2
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
None
OAuth RFC 8252 says https://www.rfc-editor.org/rfc/rfc8252#section-8.6
But Doorkeeper automatically processes authorization requests without user consent for public clients that have been previously approved. Public clients are inherently vulnerable to impersonation, their identity cannot be assured. Issue https://github.com/doorkeeper-gem/doorkeeper/issues/1589 Fix https://github.com/doorkeeper-gem/doorkeeper/pull/1646 Affected versions
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
+ 102 more Show less
0.5.0.rc1
0.6.0
0.6.0.rc1
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
1.0.0
1.0.0.rc1
1.0.0.rc2
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
2.0.0
2.0.0.alpha1
2.0.0.rc2
2.0.0.rc3
2.0.1
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
3.0.0
3.0.0.rc1
3.0.0.rc2
3.0.1
3.1.0
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.0.rc3
4.0.0.rc4
4.1.0
4.2.0
4.2.5
4.2.6
4.3.0
4.3.1
4.3.2
4.4.0
4.4.1
4.4.2
4.4.3
5.0.0
5.0.0.rc1
5.0.0.rc2
5.0.1
5.0.2
5.0.3
5.1.0
5.1.0.rc1
5.1.0.rc2
5.1.1
5.1.2
5.2.0
5.2.0.rc1
5.2.0.rc2
5.2.0.rc3
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.3.0
5.3.1
5.3.2
5.3.3
5.4.0
5.4.0.rc1
5.4.0.rc2
5.5.0
5.5.0.rc1
5.5.0.rc2
5.5.1
5.5.2
5.5.3
5.5.4
5.6.0
5.6.0.rc1
5.6.0.rc2
5.6.1
5.6.2
5.6.3
5.6.4
5.6.5
Fixed in
5.6.6
References
Updated Sep 10, 2026 · Source: OSV.dev |
5.6.3
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
5.6.2
patch
1 CVE
CVE-2023-34246
GHSA-7w2c-w47h-789w
Jun 12, 2023
Doorkeeper Improper Authentication vulnerability
4.2
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
None
OAuth RFC 8252 says https://www.rfc-editor.org/rfc/rfc8252#section-8.6
But Doorkeeper automatically processes authorization requests without user consent for public clients that have been previously approved. Public clients are inherently vulnerable to impersonation, their identity cannot be assured. Issue https://github.com/doorkeeper-gem/doorkeeper/issues/1589 Fix https://github.com/doorkeeper-gem/doorkeeper/pull/1646 Affected versions
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
+ 102 more Show less
0.5.0.rc1
0.6.0
0.6.0.rc1
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
1.0.0
1.0.0.rc1
1.0.0.rc2
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
2.0.0
2.0.0.alpha1
2.0.0.rc2
2.0.0.rc3
2.0.1
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
3.0.0
3.0.0.rc1
3.0.0.rc2
3.0.1
3.1.0
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.0.rc3
4.0.0.rc4
4.1.0
4.2.0
4.2.5
4.2.6
4.3.0
4.3.1
4.3.2
4.4.0
4.4.1
4.4.2
4.4.3
5.0.0
5.0.0.rc1
5.0.0.rc2
5.0.1
5.0.2
5.0.3
5.1.0
5.1.0.rc1
5.1.0.rc2
5.1.1
5.1.2
5.2.0
5.2.0.rc1
5.2.0.rc2
5.2.0.rc3
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.3.0
5.3.1
5.3.2
5.3.3
5.4.0
5.4.0.rc1
5.4.0.rc2
5.5.0
5.5.0.rc1
5.5.0.rc2
5.5.1
5.5.2
5.5.3
5.5.4
5.6.0
5.6.0.rc1
5.6.0.rc2
5.6.1
5.6.2
5.6.3
5.6.4
5.6.5
Fixed in
5.6.6
References
Updated Sep 10, 2026 · Source: OSV.dev |
5.6.2
patch
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
5.6.1
patch
1 CVE
CVE-2023-34246
GHSA-7w2c-w47h-789w
Jun 12, 2023
Doorkeeper Improper Authentication vulnerability
4.2
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
None
OAuth RFC 8252 says https://www.rfc-editor.org/rfc/rfc8252#section-8.6
But Doorkeeper automatically processes authorization requests without user consent for public clients that have been previously approved. Public clients are inherently vulnerable to impersonation, their identity cannot be assured. Issue https://github.com/doorkeeper-gem/doorkeeper/issues/1589 Fix https://github.com/doorkeeper-gem/doorkeeper/pull/1646 Affected versions
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
+ 102 more Show less
0.5.0.rc1
0.6.0
0.6.0.rc1
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
1.0.0
1.0.0.rc1
1.0.0.rc2
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
2.0.0
2.0.0.alpha1
2.0.0.rc2
2.0.0.rc3
2.0.1
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
3.0.0
3.0.0.rc1
3.0.0.rc2
3.0.1
3.1.0
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.0.rc3
4.0.0.rc4
4.1.0
4.2.0
4.2.5
4.2.6
4.3.0
4.3.1
4.3.2
4.4.0
4.4.1
4.4.2
4.4.3
5.0.0
5.0.0.rc1
5.0.0.rc2
5.0.1
5.0.2
5.0.3
5.1.0
5.1.0.rc1
5.1.0.rc2
5.1.1
5.1.2
5.2.0
5.2.0.rc1
5.2.0.rc2
5.2.0.rc3
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.3.0
5.3.1
5.3.2
5.3.3
5.4.0
5.4.0.rc1
5.4.0.rc2
5.5.0
5.5.0.rc1
5.5.0.rc2
5.5.1
5.5.2
5.5.3
5.5.4
5.6.0
5.6.0.rc1
5.6.0.rc2
5.6.1
5.6.2
5.6.3
5.6.4
5.6.5
Fixed in
5.6.6
References
Updated Sep 10, 2026 · Source: OSV.dev |
5.6.1
patch
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
5.6.0
minor
1 CVE
CVE-2023-34246
GHSA-7w2c-w47h-789w
Jun 12, 2023
Doorkeeper Improper Authentication vulnerability
4.2
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
None
OAuth RFC 8252 says https://www.rfc-editor.org/rfc/rfc8252#section-8.6
But Doorkeeper automatically processes authorization requests without user consent for public clients that have been previously approved. Public clients are inherently vulnerable to impersonation, their identity cannot be assured. Issue https://github.com/doorkeeper-gem/doorkeeper/issues/1589 Fix https://github.com/doorkeeper-gem/doorkeeper/pull/1646 Affected versions
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
+ 102 more Show less
0.5.0.rc1
0.6.0
0.6.0.rc1
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
1.0.0
1.0.0.rc1
1.0.0.rc2
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
2.0.0
2.0.0.alpha1
2.0.0.rc2
2.0.0.rc3
2.0.1
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
3.0.0
3.0.0.rc1
3.0.0.rc2
3.0.1
3.1.0
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.0.rc3
4.0.0.rc4
4.1.0
4.2.0
4.2.5
4.2.6
4.3.0
4.3.1
4.3.2
4.4.0
4.4.1
4.4.2
4.4.3
5.0.0
5.0.0.rc1
5.0.0.rc2
5.0.1
5.0.2
5.0.3
5.1.0
5.1.0.rc1
5.1.0.rc2
5.1.1
5.1.2
5.2.0
5.2.0.rc1
5.2.0.rc2
5.2.0.rc3
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.3.0
5.3.1
5.3.2
5.3.3
5.4.0
5.4.0.rc1
5.4.0.rc2
5.5.0
5.5.0.rc1
5.5.0.rc2
5.5.1
5.5.2
5.5.3
5.5.4
5.6.0
5.6.0.rc1
5.6.0.rc2
5.6.1
5.6.2
5.6.3
5.6.4
5.6.5
Fixed in
5.6.6
References
Updated Sep 10, 2026 · Source: OSV.dev |
5.6.0
minor
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
5.6.0.rc2
pre
1 CVE
CVE-2023-34246
GHSA-7w2c-w47h-789w
Jun 12, 2023
Doorkeeper Improper Authentication vulnerability
4.2
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
None
OAuth RFC 8252 says https://www.rfc-editor.org/rfc/rfc8252#section-8.6
But Doorkeeper automatically processes authorization requests without user consent for public clients that have been previously approved. Public clients are inherently vulnerable to impersonation, their identity cannot be assured. Issue https://github.com/doorkeeper-gem/doorkeeper/issues/1589 Fix https://github.com/doorkeeper-gem/doorkeeper/pull/1646 Affected versions
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
+ 102 more Show less
0.5.0.rc1
0.6.0
0.6.0.rc1
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
1.0.0
1.0.0.rc1
1.0.0.rc2
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
2.0.0
2.0.0.alpha1
2.0.0.rc2
2.0.0.rc3
2.0.1
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
3.0.0
3.0.0.rc1
3.0.0.rc2
3.0.1
3.1.0
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.0.rc3
4.0.0.rc4
4.1.0
4.2.0
4.2.5
4.2.6
4.3.0
4.3.1
4.3.2
4.4.0
4.4.1
4.4.2
4.4.3
5.0.0
5.0.0.rc1
5.0.0.rc2
5.0.1
5.0.2
5.0.3
5.1.0
5.1.0.rc1
5.1.0.rc2
5.1.1
5.1.2
5.2.0
5.2.0.rc1
5.2.0.rc2
5.2.0.rc3
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.3.0
5.3.1
5.3.2
5.3.3
5.4.0
5.4.0.rc1
5.4.0.rc2
5.5.0
5.5.0.rc1
5.5.0.rc2
5.5.1
5.5.2
5.5.3
5.5.4
5.6.0
5.6.0.rc1
5.6.0.rc2
5.6.1
5.6.2
5.6.3
5.6.4
5.6.5
Fixed in
5.6.6
References
Updated Sep 10, 2026 · Source: OSV.dev |
5.6.0.rc2
pre
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
5.6.0.rc1
pre
1 CVE
CVE-2023-34246
GHSA-7w2c-w47h-789w
Jun 12, 2023
Doorkeeper Improper Authentication vulnerability
4.2
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
None
OAuth RFC 8252 says https://www.rfc-editor.org/rfc/rfc8252#section-8.6
But Doorkeeper automatically processes authorization requests without user consent for public clients that have been previously approved. Public clients are inherently vulnerable to impersonation, their identity cannot be assured. Issue https://github.com/doorkeeper-gem/doorkeeper/issues/1589 Fix https://github.com/doorkeeper-gem/doorkeeper/pull/1646 Affected versions
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
+ 102 more Show less
0.5.0.rc1
0.6.0
0.6.0.rc1
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
1.0.0
1.0.0.rc1
1.0.0.rc2
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
2.0.0
2.0.0.alpha1
2.0.0.rc2
2.0.0.rc3
2.0.1
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
3.0.0
3.0.0.rc1
3.0.0.rc2
3.0.1
3.1.0
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.0.rc3
4.0.0.rc4
4.1.0
4.2.0
4.2.5
4.2.6
4.3.0
4.3.1
4.3.2
4.4.0
4.4.1
4.4.2
4.4.3
5.0.0
5.0.0.rc1
5.0.0.rc2
5.0.1
5.0.2
5.0.3
5.1.0
5.1.0.rc1
5.1.0.rc2
5.1.1
5.1.2
5.2.0
5.2.0.rc1
5.2.0.rc2
5.2.0.rc3
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.3.0
5.3.1
5.3.2
5.3.3
5.4.0
5.4.0.rc1
5.4.0.rc2
5.5.0
5.5.0.rc1
5.5.0.rc2
5.5.1
5.5.2
5.5.3
5.5.4
5.6.0
5.6.0.rc1
5.6.0.rc2
5.6.1
5.6.2
5.6.3
5.6.4
5.6.5
Fixed in
5.6.6
References
Updated Sep 10, 2026 · Source: OSV.dev |
5.6.0.rc1
pre
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
5.5.4
patch
1 CVE
CVE-2023-34246
GHSA-7w2c-w47h-789w
Jun 12, 2023
Doorkeeper Improper Authentication vulnerability
4.2
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
None
OAuth RFC 8252 says https://www.rfc-editor.org/rfc/rfc8252#section-8.6
But Doorkeeper automatically processes authorization requests without user consent for public clients that have been previously approved. Public clients are inherently vulnerable to impersonation, their identity cannot be assured. Issue https://github.com/doorkeeper-gem/doorkeeper/issues/1589 Fix https://github.com/doorkeeper-gem/doorkeeper/pull/1646 Affected versions
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
+ 102 more Show less
0.5.0.rc1
0.6.0
0.6.0.rc1
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
1.0.0
1.0.0.rc1
1.0.0.rc2
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
2.0.0
2.0.0.alpha1
2.0.0.rc2
2.0.0.rc3
2.0.1
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
3.0.0
3.0.0.rc1
3.0.0.rc2
3.0.1
3.1.0
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.0.rc3
4.0.0.rc4
4.1.0
4.2.0
4.2.5
4.2.6
4.3.0
4.3.1
4.3.2
4.4.0
4.4.1
4.4.2
4.4.3
5.0.0
5.0.0.rc1
5.0.0.rc2
5.0.1
5.0.2
5.0.3
5.1.0
5.1.0.rc1
5.1.0.rc2
5.1.1
5.1.2
5.2.0
5.2.0.rc1
5.2.0.rc2
5.2.0.rc3
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.3.0
5.3.1
5.3.2
5.3.3
5.4.0
5.4.0.rc1
5.4.0.rc2
5.5.0
5.5.0.rc1
5.5.0.rc2
5.5.1
5.5.2
5.5.3
5.5.4
5.6.0
5.6.0.rc1
5.6.0.rc2
5.6.1
5.6.2
5.6.3
5.6.4
5.6.5
Fixed in
5.6.6
References
Updated Sep 10, 2026 · Source: OSV.dev |
5.5.4
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
5.5.3
patch
1 CVE
CVE-2023-34246
GHSA-7w2c-w47h-789w
Jun 12, 2023
Doorkeeper Improper Authentication vulnerability
4.2
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
None
OAuth RFC 8252 says https://www.rfc-editor.org/rfc/rfc8252#section-8.6
But Doorkeeper automatically processes authorization requests without user consent for public clients that have been previously approved. Public clients are inherently vulnerable to impersonation, their identity cannot be assured. Issue https://github.com/doorkeeper-gem/doorkeeper/issues/1589 Fix https://github.com/doorkeeper-gem/doorkeeper/pull/1646 Affected versions
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
+ 102 more Show less
0.5.0.rc1
0.6.0
0.6.0.rc1
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
1.0.0
1.0.0.rc1
1.0.0.rc2
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
2.0.0
2.0.0.alpha1
2.0.0.rc2
2.0.0.rc3
2.0.1
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
3.0.0
3.0.0.rc1
3.0.0.rc2
3.0.1
3.1.0
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.0.rc3
4.0.0.rc4
4.1.0
4.2.0
4.2.5
4.2.6
4.3.0
4.3.1
4.3.2
4.4.0
4.4.1
4.4.2
4.4.3
5.0.0
5.0.0.rc1
5.0.0.rc2
5.0.1
5.0.2
5.0.3
5.1.0
5.1.0.rc1
5.1.0.rc2
5.1.1
5.1.2
5.2.0
5.2.0.rc1
5.2.0.rc2
5.2.0.rc3
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.3.0
5.3.1
5.3.2
5.3.3
5.4.0
5.4.0.rc1
5.4.0.rc2
5.5.0
5.5.0.rc1
5.5.0.rc2
5.5.1
5.5.2
5.5.3
5.5.4
5.6.0
5.6.0.rc1
5.6.0.rc2
5.6.1
5.6.2
5.6.3
5.6.4
5.6.5
Fixed in
5.6.6
References
Updated Sep 10, 2026 · Source: OSV.dev |
5.5.3
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
5.5.2
patch
1 CVE
CVE-2023-34246
GHSA-7w2c-w47h-789w
Jun 12, 2023
Doorkeeper Improper Authentication vulnerability
4.2
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
None
OAuth RFC 8252 says https://www.rfc-editor.org/rfc/rfc8252#section-8.6
But Doorkeeper automatically processes authorization requests without user consent for public clients that have been previously approved. Public clients are inherently vulnerable to impersonation, their identity cannot be assured. Issue https://github.com/doorkeeper-gem/doorkeeper/issues/1589 Fix https://github.com/doorkeeper-gem/doorkeeper/pull/1646 Affected versions
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
+ 102 more Show less
0.5.0.rc1
0.6.0
0.6.0.rc1
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
1.0.0
1.0.0.rc1
1.0.0.rc2
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
2.0.0
2.0.0.alpha1
2.0.0.rc2
2.0.0.rc3
2.0.1
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
3.0.0
3.0.0.rc1
3.0.0.rc2
3.0.1
3.1.0
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.0.rc3
4.0.0.rc4
4.1.0
4.2.0
4.2.5
4.2.6
4.3.0
4.3.1
4.3.2
4.4.0
4.4.1
4.4.2
4.4.3
5.0.0
5.0.0.rc1
5.0.0.rc2
5.0.1
5.0.2
5.0.3
5.1.0
5.1.0.rc1
5.1.0.rc2
5.1.1
5.1.2
5.2.0
5.2.0.rc1
5.2.0.rc2
5.2.0.rc3
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.3.0
5.3.1
5.3.2
5.3.3
5.4.0
5.4.0.rc1
5.4.0.rc2
5.5.0
5.5.0.rc1
5.5.0.rc2
5.5.1
5.5.2
5.5.3
5.5.4
5.6.0
5.6.0.rc1
5.6.0.rc2
5.6.1
5.6.2
5.6.3
5.6.4
5.6.5
Fixed in
5.6.6
References
Updated Sep 10, 2026 · Source: OSV.dev |
5.5.2
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
5.5.1
patch
1 CVE
CVE-2023-34246
GHSA-7w2c-w47h-789w
Jun 12, 2023
Doorkeeper Improper Authentication vulnerability
4.2
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
None
OAuth RFC 8252 says https://www.rfc-editor.org/rfc/rfc8252#section-8.6
But Doorkeeper automatically processes authorization requests without user consent for public clients that have been previously approved. Public clients are inherently vulnerable to impersonation, their identity cannot be assured. Issue https://github.com/doorkeeper-gem/doorkeeper/issues/1589 Fix https://github.com/doorkeeper-gem/doorkeeper/pull/1646 Affected versions
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
+ 102 more Show less
0.5.0.rc1
0.6.0
0.6.0.rc1
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
1.0.0
1.0.0.rc1
1.0.0.rc2
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
2.0.0
2.0.0.alpha1
2.0.0.rc2
2.0.0.rc3
2.0.1
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
3.0.0
3.0.0.rc1
3.0.0.rc2
3.0.1
3.1.0
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.0.rc3
4.0.0.rc4
4.1.0
4.2.0
4.2.5
4.2.6
4.3.0
4.3.1
4.3.2
4.4.0
4.4.1
4.4.2
4.4.3
5.0.0
5.0.0.rc1
5.0.0.rc2
5.0.1
5.0.2
5.0.3
5.1.0
5.1.0.rc1
5.1.0.rc2
5.1.1
5.1.2
5.2.0
5.2.0.rc1
5.2.0.rc2
5.2.0.rc3
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.3.0
5.3.1
5.3.2
5.3.3
5.4.0
5.4.0.rc1
5.4.0.rc2
5.5.0
5.5.0.rc1
5.5.0.rc2
5.5.1
5.5.2
5.5.3
5.5.4
5.6.0
5.6.0.rc1
5.6.0.rc2
5.6.1
5.6.2
5.6.3
5.6.4
5.6.5
Fixed in
5.6.6
References
Updated Sep 10, 2026 · Source: OSV.dev |
5.5.1
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
5.5.0
minor
1 CVE
CVE-2023-34246
GHSA-7w2c-w47h-789w
Jun 12, 2023
Doorkeeper Improper Authentication vulnerability
4.2
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
None
OAuth RFC 8252 says https://www.rfc-editor.org/rfc/rfc8252#section-8.6
But Doorkeeper automatically processes authorization requests without user consent for public clients that have been previously approved. Public clients are inherently vulnerable to impersonation, their identity cannot be assured. Issue https://github.com/doorkeeper-gem/doorkeeper/issues/1589 Fix https://github.com/doorkeeper-gem/doorkeeper/pull/1646 Affected versions
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
+ 102 more Show less
0.5.0.rc1
0.6.0
0.6.0.rc1
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
1.0.0
1.0.0.rc1
1.0.0.rc2
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
2.0.0
2.0.0.alpha1
2.0.0.rc2
2.0.0.rc3
2.0.1
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
3.0.0
3.0.0.rc1
3.0.0.rc2
3.0.1
3.1.0
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.0.rc3
4.0.0.rc4
4.1.0
4.2.0
4.2.5
4.2.6
4.3.0
4.3.1
4.3.2
4.4.0
4.4.1
4.4.2
4.4.3
5.0.0
5.0.0.rc1
5.0.0.rc2
5.0.1
5.0.2
5.0.3
5.1.0
5.1.0.rc1
5.1.0.rc2
5.1.1
5.1.2
5.2.0
5.2.0.rc1
5.2.0.rc2
5.2.0.rc3
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.3.0
5.3.1
5.3.2
5.3.3
5.4.0
5.4.0.rc1
5.4.0.rc2
5.5.0
5.5.0.rc1
5.5.0.rc2
5.5.1
5.5.2
5.5.3
5.5.4
5.6.0
5.6.0.rc1
5.6.0.rc2
5.6.1
5.6.2
5.6.3
5.6.4
5.6.5
Fixed in
5.6.6
References
Updated Sep 10, 2026 · Source: OSV.dev |
5.5.0
minor
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
5.5.0.rc2
pre
1 CVE
CVE-2023-34246
GHSA-7w2c-w47h-789w
Jun 12, 2023
Doorkeeper Improper Authentication vulnerability
4.2
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
None
OAuth RFC 8252 says https://www.rfc-editor.org/rfc/rfc8252#section-8.6
But Doorkeeper automatically processes authorization requests without user consent for public clients that have been previously approved. Public clients are inherently vulnerable to impersonation, their identity cannot be assured. Issue https://github.com/doorkeeper-gem/doorkeeper/issues/1589 Fix https://github.com/doorkeeper-gem/doorkeeper/pull/1646 Affected versions
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
+ 102 more Show less
0.5.0.rc1
0.6.0
0.6.0.rc1
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
1.0.0
1.0.0.rc1
1.0.0.rc2
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
2.0.0
2.0.0.alpha1
2.0.0.rc2
2.0.0.rc3
2.0.1
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
3.0.0
3.0.0.rc1
3.0.0.rc2
3.0.1
3.1.0
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.0.rc3
4.0.0.rc4
4.1.0
4.2.0
4.2.5
4.2.6
4.3.0
4.3.1
4.3.2
4.4.0
4.4.1
4.4.2
4.4.3
5.0.0
5.0.0.rc1
5.0.0.rc2
5.0.1
5.0.2
5.0.3
5.1.0
5.1.0.rc1
5.1.0.rc2
5.1.1
5.1.2
5.2.0
5.2.0.rc1
5.2.0.rc2
5.2.0.rc3
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.3.0
5.3.1
5.3.2
5.3.3
5.4.0
5.4.0.rc1
5.4.0.rc2
5.5.0
5.5.0.rc1
5.5.0.rc2
5.5.1
5.5.2
5.5.3
5.5.4
5.6.0
5.6.0.rc1
5.6.0.rc2
5.6.1
5.6.2
5.6.3
5.6.4
5.6.5
Fixed in
5.6.6
References
Updated Sep 10, 2026 · Source: OSV.dev |
5.5.0.rc2
pre
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
5.1.2
patch
1 CVE
CVE-2023-34246
GHSA-7w2c-w47h-789w
Jun 12, 2023
Doorkeeper Improper Authentication vulnerability
4.2
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
None
OAuth RFC 8252 says https://www.rfc-editor.org/rfc/rfc8252#section-8.6
But Doorkeeper automatically processes authorization requests without user consent for public clients that have been previously approved. Public clients are inherently vulnerable to impersonation, their identity cannot be assured. Issue https://github.com/doorkeeper-gem/doorkeeper/issues/1589 Fix https://github.com/doorkeeper-gem/doorkeeper/pull/1646 Affected versions
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
+ 102 more Show less
0.5.0.rc1
0.6.0
0.6.0.rc1
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
1.0.0
1.0.0.rc1
1.0.0.rc2
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
2.0.0
2.0.0.alpha1
2.0.0.rc2
2.0.0.rc3
2.0.1
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
3.0.0
3.0.0.rc1
3.0.0.rc2
3.0.1
3.1.0
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.0.rc3
4.0.0.rc4
4.1.0
4.2.0
4.2.5
4.2.6
4.3.0
4.3.1
4.3.2
4.4.0
4.4.1
4.4.2
4.4.3
5.0.0
5.0.0.rc1
5.0.0.rc2
5.0.1
5.0.2
5.0.3
5.1.0
5.1.0.rc1
5.1.0.rc2
5.1.1
5.1.2
5.2.0
5.2.0.rc1
5.2.0.rc2
5.2.0.rc3
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.3.0
5.3.1
5.3.2
5.3.3
5.4.0
5.4.0.rc1
5.4.0.rc2
5.5.0
5.5.0.rc1
5.5.0.rc2
5.5.1
5.5.2
5.5.3
5.5.4
5.6.0
5.6.0.rc1
5.6.0.rc2
5.6.1
5.6.2
5.6.3
5.6.4
5.6.5
Fixed in
5.6.6
References
Updated Sep 10, 2026 · Source: OSV.dev |
5.1.2
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
5.5.0.rc1
pre
1 CVE
CVE-2023-34246
GHSA-7w2c-w47h-789w
Jun 12, 2023
Doorkeeper Improper Authentication vulnerability
4.2
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
None
OAuth RFC 8252 says https://www.rfc-editor.org/rfc/rfc8252#section-8.6
But Doorkeeper automatically processes authorization requests without user consent for public clients that have been previously approved. Public clients are inherently vulnerable to impersonation, their identity cannot be assured. Issue https://github.com/doorkeeper-gem/doorkeeper/issues/1589 Fix https://github.com/doorkeeper-gem/doorkeeper/pull/1646 Affected versions
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
+ 102 more Show less
0.5.0.rc1
0.6.0
0.6.0.rc1
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
1.0.0
1.0.0.rc1
1.0.0.rc2
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
2.0.0
2.0.0.alpha1
2.0.0.rc2
2.0.0.rc3
2.0.1
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
3.0.0
3.0.0.rc1
3.0.0.rc2
3.0.1
3.1.0
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.0.rc3
4.0.0.rc4
4.1.0
4.2.0
4.2.5
4.2.6
4.3.0
4.3.1
4.3.2
4.4.0
4.4.1
4.4.2
4.4.3
5.0.0
5.0.0.rc1
5.0.0.rc2
5.0.1
5.0.2
5.0.3
5.1.0
5.1.0.rc1
5.1.0.rc2
5.1.1
5.1.2
5.2.0
5.2.0.rc1
5.2.0.rc2
5.2.0.rc3
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.3.0
5.3.1
5.3.2
5.3.3
5.4.0
5.4.0.rc1
5.4.0.rc2
5.5.0
5.5.0.rc1
5.5.0.rc2
5.5.1
5.5.2
5.5.3
5.5.4
5.6.0
5.6.0.rc1
5.6.0.rc2
5.6.1
5.6.2
5.6.3
5.6.4
5.6.5
Fixed in
5.6.6
References
Updated Sep 10, 2026 · Source: OSV.dev |
5.5.0.rc1
pre
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
5.4.0
minor
1 CVE
CVE-2023-34246
GHSA-7w2c-w47h-789w
Jun 12, 2023
Doorkeeper Improper Authentication vulnerability
4.2
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
None
OAuth RFC 8252 says https://www.rfc-editor.org/rfc/rfc8252#section-8.6
But Doorkeeper automatically processes authorization requests without user consent for public clients that have been previously approved. Public clients are inherently vulnerable to impersonation, their identity cannot be assured. Issue https://github.com/doorkeeper-gem/doorkeeper/issues/1589 Fix https://github.com/doorkeeper-gem/doorkeeper/pull/1646 Affected versions
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
+ 102 more Show less
0.5.0.rc1
0.6.0
0.6.0.rc1
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
1.0.0
1.0.0.rc1
1.0.0.rc2
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
2.0.0
2.0.0.alpha1
2.0.0.rc2
2.0.0.rc3
2.0.1
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
3.0.0
3.0.0.rc1
3.0.0.rc2
3.0.1
3.1.0
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.0.rc3
4.0.0.rc4
4.1.0
4.2.0
4.2.5
4.2.6
4.3.0
4.3.1
4.3.2
4.4.0
4.4.1
4.4.2
4.4.3
5.0.0
5.0.0.rc1
5.0.0.rc2
5.0.1
5.0.2
5.0.3
5.1.0
5.1.0.rc1
5.1.0.rc2
5.1.1
5.1.2
5.2.0
5.2.0.rc1
5.2.0.rc2
5.2.0.rc3
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.3.0
5.3.1
5.3.2
5.3.3
5.4.0
5.4.0.rc1
5.4.0.rc2
5.5.0
5.5.0.rc1
5.5.0.rc2
5.5.1
5.5.2
5.5.3
5.5.4
5.6.0
5.6.0.rc1
5.6.0.rc2
5.6.1
5.6.2
5.6.3
5.6.4
5.6.5
Fixed in
5.6.6
References
Updated Sep 10, 2026 · Source: OSV.dev |
5.4.0
minor
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
5.2.6
patch
1 CVE
CVE-2023-34246
GHSA-7w2c-w47h-789w
Jun 12, 2023
Doorkeeper Improper Authentication vulnerability
4.2
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
None
OAuth RFC 8252 says https://www.rfc-editor.org/rfc/rfc8252#section-8.6
But Doorkeeper automatically processes authorization requests without user consent for public clients that have been previously approved. Public clients are inherently vulnerable to impersonation, their identity cannot be assured. Issue https://github.com/doorkeeper-gem/doorkeeper/issues/1589 Fix https://github.com/doorkeeper-gem/doorkeeper/pull/1646 Affected versions
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
+ 102 more Show less
0.5.0.rc1
0.6.0
0.6.0.rc1
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
1.0.0
1.0.0.rc1
1.0.0.rc2
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
2.0.0
2.0.0.alpha1
2.0.0.rc2
2.0.0.rc3
2.0.1
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
3.0.0
3.0.0.rc1
3.0.0.rc2
3.0.1
3.1.0
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.0.rc3
4.0.0.rc4
4.1.0
4.2.0
4.2.5
4.2.6
4.3.0
4.3.1
4.3.2
4.4.0
4.4.1
4.4.2
4.4.3
5.0.0
5.0.0.rc1
5.0.0.rc2
5.0.1
5.0.2
5.0.3
5.1.0
5.1.0.rc1
5.1.0.rc2
5.1.1
5.1.2
5.2.0
5.2.0.rc1
5.2.0.rc2
5.2.0.rc3
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.3.0
5.3.1
5.3.2
5.3.3
5.4.0
5.4.0.rc1
5.4.0.rc2
5.5.0
5.5.0.rc1
5.5.0.rc2
5.5.1
5.5.2
5.5.3
5.5.4
5.6.0
5.6.0.rc1
5.6.0.rc2
5.6.1
5.6.2
5.6.3
5.6.4
5.6.5
Fixed in
5.6.6
References
Updated Sep 10, 2026 · Source: OSV.dev |
5.2.6
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
5.3.3
patch
1 CVE
CVE-2023-34246
GHSA-7w2c-w47h-789w
Jun 12, 2023
Doorkeeper Improper Authentication vulnerability
4.2
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
None
OAuth RFC 8252 says https://www.rfc-editor.org/rfc/rfc8252#section-8.6
But Doorkeeper automatically processes authorization requests without user consent for public clients that have been previously approved. Public clients are inherently vulnerable to impersonation, their identity cannot be assured. Issue https://github.com/doorkeeper-gem/doorkeeper/issues/1589 Fix https://github.com/doorkeeper-gem/doorkeeper/pull/1646 Affected versions
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
+ 102 more Show less
0.5.0.rc1
0.6.0
0.6.0.rc1
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
1.0.0
1.0.0.rc1
1.0.0.rc2
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
2.0.0
2.0.0.alpha1
2.0.0.rc2
2.0.0.rc3
2.0.1
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
3.0.0
3.0.0.rc1
3.0.0.rc2
3.0.1
3.1.0
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.0.rc3
4.0.0.rc4
4.1.0
4.2.0
4.2.5
4.2.6
4.3.0
4.3.1
4.3.2
4.4.0
4.4.1
4.4.2
4.4.3
5.0.0
5.0.0.rc1
5.0.0.rc2
5.0.1
5.0.2
5.0.3
5.1.0
5.1.0.rc1
5.1.0.rc2
5.1.1
5.1.2
5.2.0
5.2.0.rc1
5.2.0.rc2
5.2.0.rc3
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.3.0
5.3.1
5.3.2
5.3.3
5.4.0
5.4.0.rc1
5.4.0.rc2
5.5.0
5.5.0.rc1
5.5.0.rc2
5.5.1
5.5.2
5.5.3
5.5.4
5.6.0
5.6.0.rc1
5.6.0.rc2
5.6.1
5.6.2
5.6.3
5.6.4
5.6.5
Fixed in
5.6.6
References
Updated Sep 10, 2026 · Source: OSV.dev |
5.3.3
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
5.0.3
patch
1 CVE
CVE-2023-34246
GHSA-7w2c-w47h-789w
Jun 12, 2023
Doorkeeper Improper Authentication vulnerability
4.2
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
None
OAuth RFC 8252 says https://www.rfc-editor.org/rfc/rfc8252#section-8.6
But Doorkeeper automatically processes authorization requests without user consent for public clients that have been previously approved. Public clients are inherently vulnerable to impersonation, their identity cannot be assured. Issue https://github.com/doorkeeper-gem/doorkeeper/issues/1589 Fix https://github.com/doorkeeper-gem/doorkeeper/pull/1646 Affected versions
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
+ 102 more Show less
0.5.0.rc1
0.6.0
0.6.0.rc1
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
1.0.0
1.0.0.rc1
1.0.0.rc2
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
2.0.0
2.0.0.alpha1
2.0.0.rc2
2.0.0.rc3
2.0.1
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
3.0.0
3.0.0.rc1
3.0.0.rc2
3.0.1
3.1.0
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.0.rc3
4.0.0.rc4
4.1.0
4.2.0
4.2.5
4.2.6
4.3.0
4.3.1
4.3.2
4.4.0
4.4.1
4.4.2
4.4.3
5.0.0
5.0.0.rc1
5.0.0.rc2
5.0.1
5.0.2
5.0.3
5.1.0
5.1.0.rc1
5.1.0.rc2
5.1.1
5.1.2
5.2.0
5.2.0.rc1
5.2.0.rc2
5.2.0.rc3
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.3.0
5.3.1
5.3.2
5.3.3
5.4.0
5.4.0.rc1
5.4.0.rc2
5.5.0
5.5.0.rc1
5.5.0.rc2
5.5.1
5.5.2
5.5.3
5.5.4
5.6.0
5.6.0.rc1
5.6.0.rc2
5.6.1
5.6.2
5.6.3
5.6.4
5.6.5
Fixed in
5.6.6
References
Updated Sep 10, 2026 · Source: OSV.dev |
5.0.3
patch
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
5.4.0.rc2
pre
1 CVE
CVE-2023-34246
GHSA-7w2c-w47h-789w
Jun 12, 2023
Doorkeeper Improper Authentication vulnerability
4.2
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
None
OAuth RFC 8252 says https://www.rfc-editor.org/rfc/rfc8252#section-8.6
But Doorkeeper automatically processes authorization requests without user consent for public clients that have been previously approved. Public clients are inherently vulnerable to impersonation, their identity cannot be assured. Issue https://github.com/doorkeeper-gem/doorkeeper/issues/1589 Fix https://github.com/doorkeeper-gem/doorkeeper/pull/1646 Affected versions
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
+ 102 more Show less
0.5.0.rc1
0.6.0
0.6.0.rc1
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
1.0.0
1.0.0.rc1
1.0.0.rc2
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
2.0.0
2.0.0.alpha1
2.0.0.rc2
2.0.0.rc3
2.0.1
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
3.0.0
3.0.0.rc1
3.0.0.rc2
3.0.1
3.1.0
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.0.rc3
4.0.0.rc4
4.1.0
4.2.0
4.2.5
4.2.6
4.3.0
4.3.1
4.3.2
4.4.0
4.4.1
4.4.2
4.4.3
5.0.0
5.0.0.rc1
5.0.0.rc2
5.0.1
5.0.2
5.0.3
5.1.0
5.1.0.rc1
5.1.0.rc2
5.1.1
5.1.2
5.2.0
5.2.0.rc1
5.2.0.rc2
5.2.0.rc3
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.3.0
5.3.1
5.3.2
5.3.3
5.4.0
5.4.0.rc1
5.4.0.rc2
5.5.0
5.5.0.rc1
5.5.0.rc2
5.5.1
5.5.2
5.5.3
5.5.4
5.6.0
5.6.0.rc1
5.6.0.rc2
5.6.1
5.6.2
5.6.3
5.6.4
5.6.5
Fixed in
5.6.6
References
Updated Sep 10, 2026 · Source: OSV.dev |
5.4.0.rc2
pre
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
5.1.1
patch
1 CVE
CVE-2023-34246
GHSA-7w2c-w47h-789w
Jun 12, 2023
Doorkeeper Improper Authentication vulnerability
4.2
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
None
OAuth RFC 8252 says https://www.rfc-editor.org/rfc/rfc8252#section-8.6
But Doorkeeper automatically processes authorization requests without user consent for public clients that have been previously approved. Public clients are inherently vulnerable to impersonation, their identity cannot be assured. Issue https://github.com/doorkeeper-gem/doorkeeper/issues/1589 Fix https://github.com/doorkeeper-gem/doorkeeper/pull/1646 Affected versions
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
+ 102 more Show less
0.5.0.rc1
0.6.0
0.6.0.rc1
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
1.0.0
1.0.0.rc1
1.0.0.rc2
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
2.0.0
2.0.0.alpha1
2.0.0.rc2
2.0.0.rc3
2.0.1
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
3.0.0
3.0.0.rc1
3.0.0.rc2
3.0.1
3.1.0
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.0.rc3
4.0.0.rc4
4.1.0
4.2.0
4.2.5
4.2.6
4.3.0
4.3.1
4.3.2
4.4.0
4.4.1
4.4.2
4.4.3
5.0.0
5.0.0.rc1
5.0.0.rc2
5.0.1
5.0.2
5.0.3
5.1.0
5.1.0.rc1
5.1.0.rc2
5.1.1
5.1.2
5.2.0
5.2.0.rc1
5.2.0.rc2
5.2.0.rc3
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.3.0
5.3.1
5.3.2
5.3.3
5.4.0
5.4.0.rc1
5.4.0.rc2
5.5.0
5.5.0.rc1
5.5.0.rc2
5.5.1
5.5.2
5.5.3
5.5.4
5.6.0
5.6.0.rc1
5.6.0.rc2
5.6.1
5.6.2
5.6.3
5.6.4
5.6.5
Fixed in
5.6.6
References
Updated Sep 10, 2026 · Source: OSV.dev |
5.1.1
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
5.3.2
patch
1 CVE
CVE-2023-34246
GHSA-7w2c-w47h-789w
Jun 12, 2023
Doorkeeper Improper Authentication vulnerability
4.2
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
None
OAuth RFC 8252 says https://www.rfc-editor.org/rfc/rfc8252#section-8.6
But Doorkeeper automatically processes authorization requests without user consent for public clients that have been previously approved. Public clients are inherently vulnerable to impersonation, their identity cannot be assured. Issue https://github.com/doorkeeper-gem/doorkeeper/issues/1589 Fix https://github.com/doorkeeper-gem/doorkeeper/pull/1646 Affected versions
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
+ 102 more Show less
0.5.0.rc1
0.6.0
0.6.0.rc1
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
1.0.0
1.0.0.rc1
1.0.0.rc2
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
2.0.0
2.0.0.alpha1
2.0.0.rc2
2.0.0.rc3
2.0.1
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
3.0.0
3.0.0.rc1
3.0.0.rc2
3.0.1
3.1.0
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.0.rc3
4.0.0.rc4
4.1.0
4.2.0
4.2.5
4.2.6
4.3.0
4.3.1
4.3.2
4.4.0
4.4.1
4.4.2
4.4.3
5.0.0
5.0.0.rc1
5.0.0.rc2
5.0.1
5.0.2
5.0.3
5.1.0
5.1.0.rc1
5.1.0.rc2
5.1.1
5.1.2
5.2.0
5.2.0.rc1
5.2.0.rc2
5.2.0.rc3
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.3.0
5.3.1
5.3.2
5.3.3
5.4.0
5.4.0.rc1
5.4.0.rc2
5.5.0
5.5.0.rc1
5.5.0.rc2
5.5.1
5.5.2
5.5.3
5.5.4
5.6.0
5.6.0.rc1
5.6.0.rc2
5.6.1
5.6.2
5.6.3
5.6.4
5.6.5
Fixed in
5.6.6
References
Updated Sep 10, 2026 · Source: OSV.dev |
5.3.2
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
5.2.5
patch
1 CVE
CVE-2023-34246
GHSA-7w2c-w47h-789w
Jun 12, 2023
Doorkeeper Improper Authentication vulnerability
4.2
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
None
OAuth RFC 8252 says https://www.rfc-editor.org/rfc/rfc8252#section-8.6
But Doorkeeper automatically processes authorization requests without user consent for public clients that have been previously approved. Public clients are inherently vulnerable to impersonation, their identity cannot be assured. Issue https://github.com/doorkeeper-gem/doorkeeper/issues/1589 Fix https://github.com/doorkeeper-gem/doorkeeper/pull/1646 Affected versions
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
+ 102 more Show less
0.5.0.rc1
0.6.0
0.6.0.rc1
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
1.0.0
1.0.0.rc1
1.0.0.rc2
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
2.0.0
2.0.0.alpha1
2.0.0.rc2
2.0.0.rc3
2.0.1
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
3.0.0
3.0.0.rc1
3.0.0.rc2
3.0.1
3.1.0
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.0.rc3
4.0.0.rc4
4.1.0
4.2.0
4.2.5
4.2.6
4.3.0
4.3.1
4.3.2
4.4.0
4.4.1
4.4.2
4.4.3
5.0.0
5.0.0.rc1
5.0.0.rc2
5.0.1
5.0.2
5.0.3
5.1.0
5.1.0.rc1
5.1.0.rc2
5.1.1
5.1.2
5.2.0
5.2.0.rc1
5.2.0.rc2
5.2.0.rc3
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.3.0
5.3.1
5.3.2
5.3.3
5.4.0
5.4.0.rc1
5.4.0.rc2
5.5.0
5.5.0.rc1
5.5.0.rc2
5.5.1
5.5.2
5.5.3
5.5.4
5.6.0
5.6.0.rc1
5.6.0.rc2
5.6.1
5.6.2
5.6.3
5.6.4
5.6.5
Fixed in
5.6.6
References
Updated Sep 10, 2026 · Source: OSV.dev |
5.2.5
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
5.4.0.rc1
pre
1 CVE
CVE-2023-34246
GHSA-7w2c-w47h-789w
Jun 12, 2023
Doorkeeper Improper Authentication vulnerability
4.2
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
None
OAuth RFC 8252 says https://www.rfc-editor.org/rfc/rfc8252#section-8.6
But Doorkeeper automatically processes authorization requests without user consent for public clients that have been previously approved. Public clients are inherently vulnerable to impersonation, their identity cannot be assured. Issue https://github.com/doorkeeper-gem/doorkeeper/issues/1589 Fix https://github.com/doorkeeper-gem/doorkeeper/pull/1646 Affected versions
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
+ 102 more Show less
0.5.0.rc1
0.6.0
0.6.0.rc1
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
1.0.0
1.0.0.rc1
1.0.0.rc2
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
2.0.0
2.0.0.alpha1
2.0.0.rc2
2.0.0.rc3
2.0.1
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
3.0.0
3.0.0.rc1
3.0.0.rc2
3.0.1
3.1.0
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.0.rc3
4.0.0.rc4
4.1.0
4.2.0
4.2.5
4.2.6
4.3.0
4.3.1
4.3.2
4.4.0
4.4.1
4.4.2
4.4.3
5.0.0
5.0.0.rc1
5.0.0.rc2
5.0.1
5.0.2
5.0.3
5.1.0
5.1.0.rc1
5.1.0.rc2
5.1.1
5.1.2
5.2.0
5.2.0.rc1
5.2.0.rc2
5.2.0.rc3
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.3.0
5.3.1
5.3.2
5.3.3
5.4.0
5.4.0.rc1
5.4.0.rc2
5.5.0
5.5.0.rc1
5.5.0.rc2
5.5.1
5.5.2
5.5.3
5.5.4
5.6.0
5.6.0.rc1
5.6.0.rc2
5.6.1
5.6.2
5.6.3
5.6.4
5.6.5
Fixed in
5.6.6
References
Updated Sep 10, 2026 · Source: OSV.dev |
5.4.0.rc1
pre
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
5.3.1
patch
2 CVEs
CVE-2023-34246
GHSA-7w2c-w47h-789w
Jun 12, 2023
Doorkeeper Improper Authentication vulnerability
4.2
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
None
OAuth RFC 8252 says https://www.rfc-editor.org/rfc/rfc8252#section-8.6
But Doorkeeper automatically processes authorization requests without user consent for public clients that have been previously approved. Public clients are inherently vulnerable to impersonation, their identity cannot be assured. Issue https://github.com/doorkeeper-gem/doorkeeper/issues/1589 Fix https://github.com/doorkeeper-gem/doorkeeper/pull/1646 Affected versions
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
+ 102 more Show less
0.5.0.rc1
0.6.0
0.6.0.rc1
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
1.0.0
1.0.0.rc1
1.0.0.rc2
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
2.0.0
2.0.0.alpha1
2.0.0.rc2
2.0.0.rc3
2.0.1
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
3.0.0
3.0.0.rc1
3.0.0.rc2
3.0.1
3.1.0
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.0.rc3
4.0.0.rc4
4.1.0
4.2.0
4.2.5
4.2.6
4.3.0
4.3.1
4.3.2
4.4.0
4.4.1
4.4.2
4.4.3
5.0.0
5.0.0.rc1
5.0.0.rc2
5.0.1
5.0.2
5.0.3
5.1.0
5.1.0.rc1
5.1.0.rc2
5.1.1
5.1.2
5.2.0
5.2.0.rc1
5.2.0.rc2
5.2.0.rc3
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.3.0
5.3.1
5.3.2
5.3.3
5.4.0
5.4.0.rc1
5.4.0.rc2
5.5.0
5.5.0.rc1
5.5.0.rc2
5.5.1
5.5.2
5.5.3
5.5.4
5.6.0
5.6.0.rc1
5.6.0.rc2
5.6.1
5.6.2
5.6.3
5.6.4
5.6.5
Fixed in
5.6.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-10187
GHSA-j7vx-8mqj-cqp9
May 07, 2020
Exposure of Sensitive Information to an Unauthorized Actor in Doorkeeper
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactInformation disclosure vulnerability. Allows an attacker to see all PatchesThese versions have the fix:
WorkaroundsPatch Additional recommended hardening is to enable application secrets hashing (guide), available since Doorkeeper 5.1. This would render the exposed secret useless. References
Affected versions
5.0.0
5.0.1
5.0.2
5.1.0
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.3.0
5.3.1
Fixed in
5.0.3
5.1.1
5.2.5
5.3.2
References
Updated Sep 10, 2026 · Source: OSV.dev |
5.3.1
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
5.2.4
patch
2 CVEs
CVE-2023-34246
GHSA-7w2c-w47h-789w
Jun 12, 2023
Doorkeeper Improper Authentication vulnerability
4.2
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
None
OAuth RFC 8252 says https://www.rfc-editor.org/rfc/rfc8252#section-8.6
But Doorkeeper automatically processes authorization requests without user consent for public clients that have been previously approved. Public clients are inherently vulnerable to impersonation, their identity cannot be assured. Issue https://github.com/doorkeeper-gem/doorkeeper/issues/1589 Fix https://github.com/doorkeeper-gem/doorkeeper/pull/1646 Affected versions
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
+ 102 more Show less
0.5.0.rc1
0.6.0
0.6.0.rc1
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
1.0.0
1.0.0.rc1
1.0.0.rc2
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
2.0.0
2.0.0.alpha1
2.0.0.rc2
2.0.0.rc3
2.0.1
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
3.0.0
3.0.0.rc1
3.0.0.rc2
3.0.1
3.1.0
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.0.rc3
4.0.0.rc4
4.1.0
4.2.0
4.2.5
4.2.6
4.3.0
4.3.1
4.3.2
4.4.0
4.4.1
4.4.2
4.4.3
5.0.0
5.0.0.rc1
5.0.0.rc2
5.0.1
5.0.2
5.0.3
5.1.0
5.1.0.rc1
5.1.0.rc2
5.1.1
5.1.2
5.2.0
5.2.0.rc1
5.2.0.rc2
5.2.0.rc3
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.3.0
5.3.1
5.3.2
5.3.3
5.4.0
5.4.0.rc1
5.4.0.rc2
5.5.0
5.5.0.rc1
5.5.0.rc2
5.5.1
5.5.2
5.5.3
5.5.4
5.6.0
5.6.0.rc1
5.6.0.rc2
5.6.1
5.6.2
5.6.3
5.6.4
5.6.5
Fixed in
5.6.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-10187
GHSA-j7vx-8mqj-cqp9
May 07, 2020
Exposure of Sensitive Information to an Unauthorized Actor in Doorkeeper
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactInformation disclosure vulnerability. Allows an attacker to see all PatchesThese versions have the fix:
WorkaroundsPatch Additional recommended hardening is to enable application secrets hashing (guide), available since Doorkeeper 5.1. This would render the exposed secret useless. References
Affected versions
5.0.0
5.0.1
5.0.2
5.1.0
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.3.0
5.3.1
Fixed in
5.0.3
5.1.1
5.2.5
5.3.2
References
Updated Sep 10, 2026 · Source: OSV.dev |
5.2.4
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
5.3.0
minor
2 CVEs
CVE-2023-34246
GHSA-7w2c-w47h-789w
Jun 12, 2023
Doorkeeper Improper Authentication vulnerability
4.2
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
None
OAuth RFC 8252 says https://www.rfc-editor.org/rfc/rfc8252#section-8.6
But Doorkeeper automatically processes authorization requests without user consent for public clients that have been previously approved. Public clients are inherently vulnerable to impersonation, their identity cannot be assured. Issue https://github.com/doorkeeper-gem/doorkeeper/issues/1589 Fix https://github.com/doorkeeper-gem/doorkeeper/pull/1646 Affected versions
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
+ 102 more Show less
0.5.0.rc1
0.6.0
0.6.0.rc1
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
1.0.0
1.0.0.rc1
1.0.0.rc2
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
2.0.0
2.0.0.alpha1
2.0.0.rc2
2.0.0.rc3
2.0.1
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
3.0.0
3.0.0.rc1
3.0.0.rc2
3.0.1
3.1.0
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.0.rc3
4.0.0.rc4
4.1.0
4.2.0
4.2.5
4.2.6
4.3.0
4.3.1
4.3.2
4.4.0
4.4.1
4.4.2
4.4.3
5.0.0
5.0.0.rc1
5.0.0.rc2
5.0.1
5.0.2
5.0.3
5.1.0
5.1.0.rc1
5.1.0.rc2
5.1.1
5.1.2
5.2.0
5.2.0.rc1
5.2.0.rc2
5.2.0.rc3
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.3.0
5.3.1
5.3.2
5.3.3
5.4.0
5.4.0.rc1
5.4.0.rc2
5.5.0
5.5.0.rc1
5.5.0.rc2
5.5.1
5.5.2
5.5.3
5.5.4
5.6.0
5.6.0.rc1
5.6.0.rc2
5.6.1
5.6.2
5.6.3
5.6.4
5.6.5
Fixed in
5.6.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-10187
GHSA-j7vx-8mqj-cqp9
May 07, 2020
Exposure of Sensitive Information to an Unauthorized Actor in Doorkeeper
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactInformation disclosure vulnerability. Allows an attacker to see all PatchesThese versions have the fix:
WorkaroundsPatch Additional recommended hardening is to enable application secrets hashing (guide), available since Doorkeeper 5.1. This would render the exposed secret useless. References
Affected versions
5.0.0
5.0.1
5.0.2
5.1.0
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.3.0
5.3.1
Fixed in
5.0.3
5.1.1
5.2.5
5.3.2
References
Updated Sep 10, 2026 · Source: OSV.dev |
5.3.0
minor
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
5.2.3
patch
2 CVEs
CVE-2023-34246
GHSA-7w2c-w47h-789w
Jun 12, 2023
Doorkeeper Improper Authentication vulnerability
4.2
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
None
OAuth RFC 8252 says https://www.rfc-editor.org/rfc/rfc8252#section-8.6
But Doorkeeper automatically processes authorization requests without user consent for public clients that have been previously approved. Public clients are inherently vulnerable to impersonation, their identity cannot be assured. Issue https://github.com/doorkeeper-gem/doorkeeper/issues/1589 Fix https://github.com/doorkeeper-gem/doorkeeper/pull/1646 Affected versions
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
+ 102 more Show less
0.5.0.rc1
0.6.0
0.6.0.rc1
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
1.0.0
1.0.0.rc1
1.0.0.rc2
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
2.0.0
2.0.0.alpha1
2.0.0.rc2
2.0.0.rc3
2.0.1
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
3.0.0
3.0.0.rc1
3.0.0.rc2
3.0.1
3.1.0
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.0.rc3
4.0.0.rc4
4.1.0
4.2.0
4.2.5
4.2.6
4.3.0
4.3.1
4.3.2
4.4.0
4.4.1
4.4.2
4.4.3
5.0.0
5.0.0.rc1
5.0.0.rc2
5.0.1
5.0.2
5.0.3
5.1.0
5.1.0.rc1
5.1.0.rc2
5.1.1
5.1.2
5.2.0
5.2.0.rc1
5.2.0.rc2
5.2.0.rc3
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.3.0
5.3.1
5.3.2
5.3.3
5.4.0
5.4.0.rc1
5.4.0.rc2
5.5.0
5.5.0.rc1
5.5.0.rc2
5.5.1
5.5.2
5.5.3
5.5.4
5.6.0
5.6.0.rc1
5.6.0.rc2
5.6.1
5.6.2
5.6.3
5.6.4
5.6.5
Fixed in
5.6.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-10187
GHSA-j7vx-8mqj-cqp9
May 07, 2020
Exposure of Sensitive Information to an Unauthorized Actor in Doorkeeper
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactInformation disclosure vulnerability. Allows an attacker to see all PatchesThese versions have the fix:
WorkaroundsPatch Additional recommended hardening is to enable application secrets hashing (guide), available since Doorkeeper 5.1. This would render the exposed secret useless. References
Affected versions
5.0.0
5.0.1
5.0.2
5.1.0
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.3.0
5.3.1
Fixed in
5.0.3
5.1.1
5.2.5
5.3.2
References
Updated Sep 10, 2026 · Source: OSV.dev |
5.2.3
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
5.2.2
patch
2 CVEs
CVE-2023-34246
GHSA-7w2c-w47h-789w
Jun 12, 2023
Doorkeeper Improper Authentication vulnerability
4.2
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
None
OAuth RFC 8252 says https://www.rfc-editor.org/rfc/rfc8252#section-8.6
But Doorkeeper automatically processes authorization requests without user consent for public clients that have been previously approved. Public clients are inherently vulnerable to impersonation, their identity cannot be assured. Issue https://github.com/doorkeeper-gem/doorkeeper/issues/1589 Fix https://github.com/doorkeeper-gem/doorkeeper/pull/1646 Affected versions
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
+ 102 more Show less
0.5.0.rc1
0.6.0
0.6.0.rc1
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
1.0.0
1.0.0.rc1
1.0.0.rc2
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
2.0.0
2.0.0.alpha1
2.0.0.rc2
2.0.0.rc3
2.0.1
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
3.0.0
3.0.0.rc1
3.0.0.rc2
3.0.1
3.1.0
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.0.rc3
4.0.0.rc4
4.1.0
4.2.0
4.2.5
4.2.6
4.3.0
4.3.1
4.3.2
4.4.0
4.4.1
4.4.2
4.4.3
5.0.0
5.0.0.rc1
5.0.0.rc2
5.0.1
5.0.2
5.0.3
5.1.0
5.1.0.rc1
5.1.0.rc2
5.1.1
5.1.2
5.2.0
5.2.0.rc1
5.2.0.rc2
5.2.0.rc3
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.3.0
5.3.1
5.3.2
5.3.3
5.4.0
5.4.0.rc1
5.4.0.rc2
5.5.0
5.5.0.rc1
5.5.0.rc2
5.5.1
5.5.2
5.5.3
5.5.4
5.6.0
5.6.0.rc1
5.6.0.rc2
5.6.1
5.6.2
5.6.3
5.6.4
5.6.5
Fixed in
5.6.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-10187
GHSA-j7vx-8mqj-cqp9
May 07, 2020
Exposure of Sensitive Information to an Unauthorized Actor in Doorkeeper
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactInformation disclosure vulnerability. Allows an attacker to see all PatchesThese versions have the fix:
WorkaroundsPatch Additional recommended hardening is to enable application secrets hashing (guide), available since Doorkeeper 5.1. This would render the exposed secret useless. References
Affected versions
5.0.0
5.0.1
5.0.2
5.1.0
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.3.0
5.3.1
Fixed in
5.0.3
5.1.1
5.2.5
5.3.2
References
Updated Sep 10, 2026 · Source: OSV.dev |
5.2.2
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
5.2.1
patch
2 CVEs
CVE-2023-34246
GHSA-7w2c-w47h-789w
Jun 12, 2023
Doorkeeper Improper Authentication vulnerability
4.2
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
None
OAuth RFC 8252 says https://www.rfc-editor.org/rfc/rfc8252#section-8.6
But Doorkeeper automatically processes authorization requests without user consent for public clients that have been previously approved. Public clients are inherently vulnerable to impersonation, their identity cannot be assured. Issue https://github.com/doorkeeper-gem/doorkeeper/issues/1589 Fix https://github.com/doorkeeper-gem/doorkeeper/pull/1646 Affected versions
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
+ 102 more Show less
0.5.0.rc1
0.6.0
0.6.0.rc1
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
1.0.0
1.0.0.rc1
1.0.0.rc2
1.1.0
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
2.0.0
2.0.0.alpha1
2.0.0.rc2
2.0.0.rc3
2.0.1
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
3.0.0
3.0.0.rc1
3.0.0.rc2
3.0.1
3.1.0
4.0.0
4.0.0.rc1
4.0.0.rc2
4.0.0.rc3
4.0.0.rc4
4.1.0
4.2.0
4.2.5
4.2.6
4.3.0
4.3.1
4.3.2
4.4.0
4.4.1
4.4.2
4.4.3
5.0.0
5.0.0.rc1
5.0.0.rc2
5.0.1
5.0.2
5.0.3
5.1.0
5.1.0.rc1
5.1.0.rc2
5.1.1
5.1.2
5.2.0
5.2.0.rc1
5.2.0.rc2
5.2.0.rc3
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.3.0
5.3.1
5.3.2
5.3.3
5.4.0
5.4.0.rc1
5.4.0.rc2
5.5.0
5.5.0.rc1
5.5.0.rc2
5.5.1
5.5.2
5.5.3
5.5.4
5.6.0
5.6.0.rc1
5.6.0.rc2
5.6.1
5.6.2
5.6.3
5.6.4
5.6.5
Fixed in
5.6.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-10187
GHSA-j7vx-8mqj-cqp9
May 07, 2020
Exposure of Sensitive Information to an Unauthorized Actor in Doorkeeper
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactInformation disclosure vulnerability. Allows an attacker to see all PatchesThese versions have the fix:
WorkaroundsPatch Additional recommended hardening is to enable application secrets hashing (guide), available since Doorkeeper 5.1. This would render the exposed secret useless. References
Affected versions
5.0.0
5.0.1
5.0.2
5.1.0
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.3.0
5.3.1
Fixed in
5.0.3
5.1.1
5.2.5
5.3.2
References
Updated Sep 10, 2026 · Source: OSV.dev |
5.2.1
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|