Debian Package Tracker
Register | Log in
Subscribe

ruby-doorkeeper-openid-connect

OpenID Connect extension for Doorkeeper

Choose email to subscribe with

general
  • source: ruby-doorkeeper-openid-connect (main)
  • version: 1.10.5-1
  • maintainer: Debian Ruby Team (archive) (DMD)
  • uploaders: Pirate Praveen [DMD]
  • arch: all
  • std-ver: 4.7.4
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 1.7.4-2
  • oldstable: 1.8.0-1
  • stable: 1.8.7-1
  • testing: 1.10.5-1
  • unstable: 1.10.5-1
versioned links
  • 1.7.4-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.8.0-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.8.7-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.10.5-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • ruby-doorkeeper-openid-connect
action needed
A new upstream version is available: 2.0.0.beta1 high
A new upstream version 2.0.0.beta1 is available, you should consider packaging it.
Created: 2026-08-20 Last update: 2026-08-30 00:30
2 security issues in trixie high

There are 2 open security issues in trixie.

2 important issues:
  • CVE-2026-44476: Doorkeeper is an OAuth 2 provider for Ruby on Rails. In version 1.9.0, an attacker who knows only a dynamically registered client's client_id, which is public information, can authenticate as that client at the token endpoint and obtain an access token without providing its client_secret. This occurs because the Dynamic Client Registration feature creates applications with confidential: false hard-coded, even though the registration response returns a client_secret and advertises support for the client_secret_basic and client_secret_post authentication methods; since Doorkeeper treats a blank or missing secret as valid for non-confidential (public) clients, the secret is never verified. Only projects that have explicitly enabled Dynamic Client Registration, which is disabled by default, are affected. This issue is fixed in version 1.10.0.
  • CVE-2026-70665: Doorkeeper OpenID Connect implements an OpenID Connect authentication provider for Rails applications on top of Doorkeeper. Prior to 1.10.4, the Dynamic Client Registration (DCR) endpoint persists client-supplied scopes without validating them against the server's configured scope set. Under certain conditions, this allows a self-registered client to obtain scopes beyond what the server intended to grant. In DynamicClientRegistrationController#application_params, the scopes attribute is assigned directly from params[:scope] with no validation against Doorkeeper.configuration.scopes or optional_scopes. Combined with enforce_configured_scopes being off by default and Doorkeeper's ScopeChecker prioritizing application-level scopes over server-level scopes, this creates a privilege escalation path. This issue is fixed in version 1.10.4.
Created: 2026-08-26 Last update: 2026-08-26 17:30
2 security issues in bullseye high

There are 2 open security issues in bullseye.

2 important issues:
  • CVE-2026-44476: Doorkeeper is an OAuth 2 provider for Ruby on Rails. In version 1.9.0, an attacker who knows only a dynamically registered client's client_id, which is public information, can authenticate as that client at the token endpoint and obtain an access token without providing its client_secret. This occurs because the Dynamic Client Registration feature creates applications with confidential: false hard-coded, even though the registration response returns a client_secret and advertises support for the client_secret_basic and client_secret_post authentication methods; since Doorkeeper treats a blank or missing secret as valid for non-confidential (public) clients, the secret is never verified. Only projects that have explicitly enabled Dynamic Client Registration, which is disabled by default, are affected. This issue is fixed in version 1.10.0.
  • CVE-2026-70665: Doorkeeper OpenID Connect implements an OpenID Connect authentication provider for Rails applications on top of Doorkeeper. Prior to 1.10.4, the Dynamic Client Registration (DCR) endpoint persists client-supplied scopes without validating them against the server's configured scope set. Under certain conditions, this allows a self-registered client to obtain scopes beyond what the server intended to grant. In DynamicClientRegistrationController#application_params, the scopes attribute is assigned directly from params[:scope] with no validation against Doorkeeper.configuration.scopes or optional_scopes. Combined with enforce_configured_scopes being off by default and Doorkeeper's ScopeChecker prioritizing application-level scopes over server-level scopes, this creates a privilege escalation path. This issue is fixed in version 1.10.4.
Created: 2026-08-26 Last update: 2026-08-26 17:30
2 security issues in bookworm high

There are 2 open security issues in bookworm.

2 important issues:
  • CVE-2026-44476: Doorkeeper is an OAuth 2 provider for Ruby on Rails. In version 1.9.0, an attacker who knows only a dynamically registered client's client_id, which is public information, can authenticate as that client at the token endpoint and obtain an access token without providing its client_secret. This occurs because the Dynamic Client Registration feature creates applications with confidential: false hard-coded, even though the registration response returns a client_secret and advertises support for the client_secret_basic and client_secret_post authentication methods; since Doorkeeper treats a blank or missing secret as valid for non-confidential (public) clients, the secret is never verified. Only projects that have explicitly enabled Dynamic Client Registration, which is disabled by default, are affected. This issue is fixed in version 1.10.0.
  • CVE-2026-70665: Doorkeeper OpenID Connect implements an OpenID Connect authentication provider for Rails applications on top of Doorkeeper. Prior to 1.10.4, the Dynamic Client Registration (DCR) endpoint persists client-supplied scopes without validating them against the server's configured scope set. Under certain conditions, this allows a self-registered client to obtain scopes beyond what the server intended to grant. In DynamicClientRegistrationController#application_params, the scopes attribute is assigned directly from params[:scope] with no validation against Doorkeeper.configuration.scopes or optional_scopes. Combined with enforce_configured_scopes being off by default and Doorkeeper's ScopeChecker prioritizing application-level scopes over server-level scopes, this creates a privilege escalation path. This issue is fixed in version 1.10.4.
Created: 2026-08-26 Last update: 2026-08-26 17:30
news
[rss feed]
  • [2026-07-24] ruby-doorkeeper-openid-connect 1.10.5-1 MIGRATED to testing (Debian testing watch)
  • [2026-07-18] Accepted ruby-doorkeeper-openid-connect 1.10.5-1 (source) into unstable (Sergei Stepanenkov) (signed by: Praveen Arimbrathodiyil)
  • [2026-06-24] ruby-doorkeeper-openid-connect 1.10.1-1 MIGRATED to testing (Debian testing watch)
  • [2026-06-19] Accepted ruby-doorkeeper-openid-connect 1.10.1-1 (source) into unstable (Simon Quigley)
  • [2026-05-02] ruby-doorkeeper-openid-connect 1.9.0-1 MIGRATED to testing (Debian testing watch)
  • [2026-04-26] Accepted ruby-doorkeeper-openid-connect 1.9.0-1 (source) into unstable (Simon Quigley)
  • [2026-03-14] ruby-doorkeeper-openid-connect 1.8.11-2 MIGRATED to testing (Debian testing watch)
  • [2026-03-08] Accepted ruby-doorkeeper-openid-connect 1.8.11-2 (source) into unstable (Simon Quigley)
  • [2025-11-04] ruby-doorkeeper-openid-connect 1.8.11-1 MIGRATED to testing (Debian testing watch)
  • [2025-10-29] Accepted ruby-doorkeeper-openid-connect 1.8.11-1 (source) into unstable (Simon Quigley)
  • [2023-07-14] ruby-doorkeeper-openid-connect 1.8.7-1 MIGRATED to testing (Debian testing watch)
  • [2023-07-09] Accepted ruby-doorkeeper-openid-connect 1.8.7-1 (source) into unstable (Pirate Praveen) (signed by: Praveen Arimbrathodiyil)
  • [2023-07-04] ruby-doorkeeper-openid-connect 1.8.5-2 MIGRATED to testing (Debian testing watch)
  • [2023-06-28] Accepted ruby-doorkeeper-openid-connect 1.8.5-2 (source) into unstable (Pirate Praveen) (signed by: Praveen Arimbrathodiyil)
  • [2023-05-04] Accepted ruby-doorkeeper-openid-connect 1.8.5-1 (source) into experimental (Pirate Praveen) (signed by: Praveen Arimbrathodiyil)
  • [2022-11-06] ruby-doorkeeper-openid-connect 1.8.0-1 MIGRATED to testing (Debian testing watch)
  • [2022-10-28] ruby-doorkeeper-openid-connect REMOVED from testing (Debian testing watch)
  • [2022-10-28] ruby-doorkeeper-openid-connect REMOVED from testing (Debian testing watch)
  • [2022-09-19] ruby-doorkeeper-openid-connect 1.8.0-1 MIGRATED to testing (Debian testing watch)
  • [2022-07-10] ruby-doorkeeper-openid-connect REMOVED from testing (Debian testing watch)
  • [2021-09-01] ruby-doorkeeper-openid-connect 1.8.0-1 MIGRATED to testing (Debian testing watch)
  • [2021-08-27] Accepted ruby-doorkeeper-openid-connect 1.8.0-1 (source) into unstable (Pirate Praveen) (signed by: Praveen Arimbrathodiyil)
  • [2021-03-11] Accepted ruby-doorkeeper-openid-connect 1.7.5-2 (source) into experimental (Pirate Praveen) (signed by: Praveen Arimbrathodiyil)
  • [2021-03-09] Accepted ruby-doorkeeper-openid-connect 1.7.5-1 (source) into experimental (Pirate Praveen) (signed by: Praveen Arimbrathodiyil)
  • [2020-12-03] Accepted ruby-doorkeeper-openid-connect 1.7.4-2~bpo10+1 (source all) into buster-backports (Pirate Praveen) (signed by: Praveen Arimbrathodiyil)
  • [2020-12-03] ruby-doorkeeper-openid-connect 1.7.4-2 MIGRATED to testing (Debian testing watch)
  • [2020-11-28] Accepted ruby-doorkeeper-openid-connect 1.7.4-2 (source) into unstable (Sruthi Chandran)
  • [2020-11-26] Accepted ruby-doorkeeper-openid-connect 1.7.4-1 (source) into unstable (Abraham Raji) (signed by: Sruthi Chandran)
  • [2020-04-04] Accepted ruby-doorkeeper-openid-connect 1.6.3-2~bpo10+1 (source all) into buster-backports (Pirate Praveen) (signed by: Praveen Arimbrathodiyil)
  • [2020-04-03] ruby-doorkeeper-openid-connect 1.6.3-2 MIGRATED to testing (Debian testing watch)
  • 1
  • 2
bugs [bug history graph]
  • all: 0
links
  • homepage
  • lintian
  • buildd: logs, reproducibility
  • popcon
  • browse source code
  • other distros
  • security tracker
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 1.10.5-1

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing