CVE-2018-1000211: Doorkeeper Project Doorkeeper

High severity, CVSS 7.5. EPSS: 1.6% chance of exploitation in the next 30 days.

Doorkeeper version 4.2.0 and later contains a Incorrect Access Control vulnerability in Token revocation API's authorized method that can result in Access tokens are not revoked for public OAuth apps, leaking access until expiry.

Affected products

Published 2018-07-13. Last modified 2026-06-17.