CVE-2023-34246

Doorkeeper is an OAuth 2 provider for Ruby on Rails / Grape. Prior to version 5.6.6, Doorkeeper automatically processes authorization requests without user consent for public clients that have been pr ...

Continue Reading
CVE-2023-34246

Doorkeeper is an OAuth 2 provider for Ruby on Rails / Grape. Prior to ...Read More ...

Continue Reading
Doorkeeper Improper Authentication vulnerability

OAuth RFC 8252 says https://www.rfc-editor.org/rfc/rfc8252#section-8.6 > the authorization server SHOULD NOT process authorization requests automatically without user consent or interaction, excep ...

Continue Reading
Doorkeeper Improper Authentication vulnerability

OAuth RFC 8252 says https://www.rfc-editor.org/rfc/rfc8252#section-8.6 > the authorization server SHOULD NOT process authorization requests automatically without user consent or interaction, excep ...

Continue Reading
CVE-2023-34246

Doorkeeper is an OAuth 2 provider for Ruby on Rails / Grape. Prior to version 5.6.6, Doorkeeper automatically processes authorization requests without user consent for public clients that have been pr ...

Continue Reading
How to Improve Your API Security Posture

[![API Security Posture](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAQAAAC1HAwCAAAAC0lEQVR42mP8Xw8AAoMBgDTD2qgAAAAASUVORK5CYII=)]() APIs, more formally known as application programming int ...

Continue Reading
Cross-site Scripting (XSS)

com.liferay.oauth2.provider.service is vulnerable to Cross-site Scripting (XSS). The vulnerability exists in the OAuth 2.0 module's `OAuth2ProviderApplicationRedirect` class in the library, which allo ...

Continue Reading

CVSS3 - MEDIUM

CVSS2 - MEDIUM

This Week in Spring – June 6th, 2023

Hi, Spring fans! Welcome to another installment of _This Week in Spring_! And what an insane week it's been! Long story short, I've spent 10-12 hours a day over the last five days migrating a dozen di ...

Continue Reading

Back to Main

Subscribe for the latest news: