{"id":"GHSA-j7vx-8mqj-cqp9","summary":"Exposure of Sensitive Information to an Unauthorized Actor in Doorkeeper","details":"### Impact\nInformation disclosure vulnerability. Allows an attacker to see all `Doorkeeper::Application` model attribute values (including secrets) using authorized applications controller if it's enabled (GET /oauth/authorized_applications.json).\n\n### Patches\n\nThese versions have the fix:\n\n* 5.0.3\n* 5.1.1\n* 5.2.5\n* 5.3.2\n\n### Workarounds\nPatch `Doorkeeper::Application` model `#as_json(options = {})` method and define only those attributes you want to expose.\n\nAdditional recommended hardening is to enable application secrets hashing ([guide](https://doorkeeper.gitbook.io/guides/security/token-and-application-secrets)), available since Doorkeeper 5.1. This would render the exposed secret useless.\n\n### References\n\n- Commit with fix: https://github.com/doorkeeper-gem/doorkeeper/commit/25d038022c2fcad45af5b73f9d003cf38ff491f6\n- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10187","aliases":["CVE-2020-10187"],"modified":"2026-09-10T03:48:45.853099273Z","published":"2020-05-07T21:11:07Z","database_specific":{"nvd_published_at":"2020-05-04T14:15:00Z","cwe_ids":["CWE-862"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2020-05-07T21:09:24Z"},"references":[{"type":"WEB","url":"https://github.com/doorkeeper-gem/doorkeeper/security/advisories/GHSA-j7vx-8mqj-cqp9"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-10187"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/pull/446"},{"type":"WEB","url":"https://github.com/doorkeeper-gem/doorkeeper/commit/25d038022c2fcad45af5b73f9d003cf38ff491f6"},{"type":"WEB","url":"https://github.com/doorkeeper-gem/doorkeeper/releases"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/doorkeeper/CVE-2020-10187.yml"}],"affected":[{"package":{"name":"doorkeeper","ecosystem":"RubyGems","purl":"pkg:gem/doorkeeper"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.0.0"},{"fixed":"5.0.3"}]}],"versions":["5.0.0","5.0.1","5.0.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/05/GHSA-j7vx-8mqj-cqp9/GHSA-j7vx-8mqj-cqp9.json"}},{"package":{"name":"doorkeeper","ecosystem":"RubyGems","purl":"pkg:gem/doorkeeper"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.1.0"},{"fixed":"5.1.1"}]}],"versions":["5.1.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/05/GHSA-j7vx-8mqj-cqp9/GHSA-j7vx-8mqj-cqp9.json"}},{"package":{"name":"doorkeeper","ecosystem":"RubyGems","purl":"pkg:gem/doorkeeper"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.2.0"},{"fixed":"5.2.5"}]}],"versions":["5.2.0","5.2.1","5.2.2","5.2.3","5.2.4"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/05/GHSA-j7vx-8mqj-cqp9/GHSA-j7vx-8mqj-cqp9.json"}},{"package":{"name":"doorkeeper","ecosystem":"RubyGems","purl":"pkg:gem/doorkeeper"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.3.0"},{"fixed":"5.3.2"}]}],"versions":["5.3.0","5.3.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/05/GHSA-j7vx-8mqj-cqp9/GHSA-j7vx-8mqj-cqp9.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}