<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T18:59:12.009990+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2020-avi-257</id>
    <title>certfr-2020-avi-257 — De multiples vulnérabilités ont été découvertes dans GitLab. Elles
permettent à un attaquant de provoquer un déni de se…</title>
    <updated>2026-10-05T18:59:12.134138+00:00</updated>
    <content>certfr-2020-avi-257</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2020-avi-257"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2020-31762</id>
    <title>cnvd-2020-31762</title>
    <updated>2026-10-05T18:59:12.134183+00:00</updated>
    <content>cnvd-2020-31762</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2020-31762"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-39686</id>
    <title>EUVD-2026-39686</title>
    <updated>2026-10-05T18:59:12.134200+00:00</updated>
    <content>EUVD-2026-39686</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-39686"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2020-10187</id>
    <title>fkie_cve-2020-10187</title>
    <updated>2026-10-05T18:59:12.134213+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Doorkeeper version 5.0.0 and later contains an information disclosure vulnerability that allows an attacker to retrieve the client secret only intended for the OAuth application owner. After authorizing the application and allowing access, the attacker simply needs to request the list of their authorized applications in a JSON format (usually GET /oauth/authorized_applications.json). An application is vulnerable if the authorized applications controller is enabled.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2020-10187"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-j7vx-8mqj-cqp9</id>
    <title>GHSA-j7vx-8mqj-cqp9 — Exposure of Sensitive Information to an Unauthorized Actor in Doorkeeper</title>
    <updated>2026-10-05T18:59:12.134244+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> RubyGems: doorkeeper</p>
<p>### Impact
Information disclosure vulnerability. Allows an attacker to see all `Doorkeeper::Application` model attribute values (including secrets) using authorized applications controller if it's enabled (GET /oauth/authorized_applications.json).</p>
<p>### Patches</p>
<p>These versions have the fix:</p>
<p>* 5.0.3
* 5.1.1
* 5.2.5
* 5.3.2</p>
<p>### Workarounds
Patch `Doorkeeper::Application` model `#as_json(options = {})` method and define only those attributes you want to expose.</p>
<p>Additional recommended hardening is to enable application secrets hashing ([guide](https://doorkeeper.gitbook.io/guides/security/token-and-application-secrets)), available since Doorkeeper 5.1. This would render the exposed secret useless.</p>
<p>### References</p>
<p>- Commit with fix: https://github.com/doorkeeper-gem/doorkeeper/commit/25d038022c2fcad45af5b73f9d003cf38ff491f6
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10187</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-j7vx-8mqj-cqp9"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2020-10187</id>
    <title>gsd-2020-10187</title>
    <updated>2026-10-05T18:59:12.134280+00:00</updated>
    <content>gsd-2020-10187</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2020-10187"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-10187</id>
    <title>Withdrawn: UBUNTU-CVE-2020-10187</title>
    <updated>2026-10-05T18:59:12.134292+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: ruby-doorkeeper, Ubuntu:Pro:18.04:LTS: ruby-doorkeeper, Ubuntu:20.04:LTS: ruby-doorkeeper</p>
<p>Doorkeeper version 5.0.0 and later contains an information disclosure vulnerability that allows an attacker to retrieve the client secret only intended for the OAuth application owner. After authorizing the application and allowing access, the attacker simply needs to request the list of their authorized applications in a JSON format (usually GET /oauth/authorized_applications.json). An application is vulnerable if the authorized applications controller is enabled.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-10187"/>
  </entry>
</feed>
