[USN-6210-1] Doorkeeper vulnerability

Paulo Flabiano Smorigo pfsmorigo at canonical.com
Fri Jul 7 22:45:05 UTC 2023


==========================================================================
Ubuntu Security Notice USN-6210-1
July 07, 2023

ruby-doorkeeper vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 23.04
- Ubuntu 22.10
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS (Available with Ubuntu Pro)
- Ubuntu 16.04 LTS (Available with Ubuntu Pro)

Summary:

Doorkeeper could be made to expose sensitive information over the
network.

Software Description:
- ruby-doorkeeper: OAuth 2 provider for Rails and Grape

Details:

It was discovered that Doorkeeper incorrectly performed authorization checks
for public clients that have been previous approved. An attacker could
potentially exploit these in order to impersonate another user and obtain
sensitive information.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 23.04:
  ruby-doorkeeper                 5.5.0-2ubuntu0.23.04.1

Ubuntu 22.10:
  ruby-doorkeeper                 5.5.0-2ubuntu0.22.10.1

Ubuntu 22.04 LTS:
  ruby-doorkeeper                 5.5.0-2ubuntu0.22.04.1

Ubuntu 20.04 LTS:
  ruby-doorkeeper                 5.0.2-2ubuntu0.1

Ubuntu 18.04 LTS (Available with Ubuntu Pro):
  ruby-doorkeeper                 4.3.1-1ubuntu0.1~esm1

Ubuntu 16.04 LTS (Available with Ubuntu Pro):
  ruby-doorkeeper                 2.2.1-1ubuntu0.1~esm1

After a standard system update you need to restart any applications using
Doorkeeper to make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-6210-1
  CVE-2023-34246

Package Information:
  https://launchpad.net/ubuntu/+source/ruby-doorkeeper/5.5.0-2ubuntu0.23.04.1
  https://launchpad.net/ubuntu/+source/ruby-doorkeeper/5.5.0-2ubuntu0.22.10.1
  https://launchpad.net/ubuntu/+source/ruby-doorkeeper/5.5.0-2ubuntu0.22.04.1
  https://launchpad.net/ubuntu/+source/ruby-doorkeeper/5.0.2-2ubuntu0.1
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 833 bytes
Desc: not available
URL: <https://lists.ubuntu.com/archives/ubuntu-security-announce/attachments/20230707/806a1919/attachment.sig>


More information about the ubuntu-security-announce mailing list