Doorkeeper version 5.0.0 and later contains an information disclosure vulnerability that allows an attacker to retrieve the client secret only intended for the OAuth application owner
Published May 4, 2020
7.5
HIGHCVSS 3.1
EPSS 2.07%
Description
Doorkeeper version 5.0.0 and later contains an information disclosure vulnerability that allows an attacker to retrieve the client secret only intended for the OAuth application owner. After authorizing the application and allowing access, the attacker simply needs to request the list of their authorized applications in a JSON format (usually GET /oauth/authorized_applications.json). An application is vulnerable if the authorized applications controller is enabled.
Affected products
No data.
- ≥ 5.0.0 · < 5.0.3
- ≥ 5.1.0 · < 5.1.1
- ≥ 5.2.0 · < 5.2.5
- ≥ 5.3.0 · < 5.3.2
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
No CVSS v3.0 score for this CVE.
AV:N/AC:M/Au:N/C:P/I:N/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v5
Table of values (13 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 2.07% (0.02067) | 80.73th | v5 (v2026.06.15) |
| Sep 19, 2026 | 2.07% (0.02067) | 80.54th | v5 (v2026.06.15) |
| Jul 20, 2024 | 0.15% (0.00148) | 51.39th | v3 (v2023.03.01) |
| Feb 22, 2024 | 0.15% (0.00153) | 50.47th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.13% (0.00128) | 45.76th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.02% (0.01018) | 40.69th | v2 (v2022.01.01) |
| Sep 10, 2022 | 1.02% (0.01018) | 38.88th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.02% (0.01018) | 36.86th | v2 (v2022.01.01) |
| Feb 4, 2022 | 15.35% (0.15351) | 91.59th | v2 (v2022.01.01) |
| Feb 3, 2022 | 4.50% (0.04504) | 76.47th | v1 |
| Jan 6, 2022 | 4.50% (0.04504) | 76.26th | v1 |
| Sep 1, 2021 | 1.04% (0.01040) | 64.49th | v1 |
| Apr 14, 2021 | 1.04% (0.01040) | 0.00th | v1 |
References (7)
- https://github.com/advisories/GHSA-j7vx-8mqj-cqp9 Advisory
- https://github.com/doorkeeper-gem/doorkeeper/commit/25d038022c2fcad45af5b73f9d003cf38ff491f6 x_refsource_MISCPatchThird Party Advisory
- https://github.com/doorkeeper-gem/doorkeeper/releases x_refsource_MISCRelease NotesThird Party Advisory
- https://github.com/doorkeeper-gem/doorkeeper/security/advisories/GHSA-j7vx-8mqj-cqp9 x_refsource_MISCPatchThird Party Advisory
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/doorkeeper/CVE-2020-10187.yml
- https://github.com/rubysec/ruby-advisory-db/pull/446 x_refsource_MISCPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-10187
| Link | Providers | Tags |
|---|---|---|
| https://github.com/advisories/GHSA-j7vx-8mqj-cqp9 | Advisory | |
| https://github.com/doorkeeper-gem/doorkeeper/commit/25d038022c2fcad45af5b73f9d003cf38ff491f6 | x_refsource_MISCPatchThird Party Advisory | |
| https://github.com/doorkeeper-gem/doorkeeper/releases | x_refsource_MISCRelease NotesThird Party Advisory | |
| https://github.com/doorkeeper-gem/doorkeeper/security/advisories/GHSA-j7vx-8mqj-cqp9 | x_refsource_MISCPatchThird Party Advisory | |
| https://github.com/rubysec/ruby-advisory-db/blob/master/gems/doorkeeper/CVE-2020-10187.yml | ||
| https://github.com/rubysec/ruby-advisory-db/pull/446 | x_refsource_MISCPatchThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2020-10187 |
Change history (0)
No recorded changes yet.