{"id":"CVE-2023-34246","aliases":["GHSA-7w2c-w47h-789w"],"url":"https://o3.security/vulnerability/CVE-2023-34246","summary":"Doorkeeper Improper Authentication vulnerability","details":"OAuth RFC 8252 says  https://www.rfc-editor.org/rfc/rfc8252#section-8.6\n\n> the authorization server SHOULD NOT process authorization requests automatically without user consent or interaction, except when the identity of the client can be assured. **This includes the case where the user has previously approved an authorization request for a given client id**\n\nBut Doorkeeper automatically processes authorization requests without user consent for public clients that have been previously approved. Public clients are inherently vulnerable to impersonation, their identity cannot be assured.\n\nIssue https://github.com/doorkeeper-gem/doorkeeper/issues/1589\n\nFix https://github.com/doorkeeper-gem/doorkeeper/pull/1646","published":"2023-06-12T16:33:05.704Z","modified":"2026-08-12T03:51:13.321198268Z","cvss":{"score":4.2,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N"},"epss":{"score":0.00716,"percentile":0.50336,"asOf":"2026-08-08"},"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"RubyGems","name":"doorkeeper","fixedVersion":"5.6.6"}],"fix":{"url":"https://github.com/doorkeeper-gem/doorkeeper/pull/1646","label":"doorkeeper-gem/doorkeeper#1646"},"references":[{"type":"WEB","url":"https://github.com/doorkeeper-gem/doorkeeper/releases/tag/v5.6.6"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2023/07/msg00016.html"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2024/12/msg00010.html"},{"type":"WEB","url":"https://www.rfc-editor.org/rfc/rfc8252#section-8.6"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/34xxx/CVE-2023-34246.json"},{"type":"ADVISORY","url":"https://github.com/doorkeeper-gem/doorkeeper/security/advisories/GHSA-7w2c-w47h-789w"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-34246"},{"type":"REPORT","url":"https://github.com/doorkeeper-gem/doorkeeper/issues/1589"},{"type":"FIX","url":"https://github.com/doorkeeper-gem/doorkeeper/pull/1646"},{"type":"PACKAGE","url":"https://github.com/doorkeeper-gem/doorkeeper"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/doorkeeper/CVE-2023-34246.yml"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:13.321198268Z"}}