CVE-2016-6582: The Doorkeeper gem before 4.2.0 for Ruby might allow remote attackers ...

Severity: Critical

CVSS Score: 9.1

The Doorkeeper gem before 4.2.0 for Ruby might allow remote attackers to conduct replay attacks or revoke arbitrary tokens by leveraging failure to implement the OAuth 2.0 Token Revocation specification.