DEV Community

Stefan Sundin
Stefan Sundin

Posted on

3 2

CVE-2020-10187

About two months ago, I found a CVE in a Ruby gem called Doorkeeper, and today the details were finally made public.

I found a couple of companies that were vulnerable in the wild, so it took some time to contact them and wait for them to patch their websites before the vulnerability was made public. I also worked with the gem maintainer to release a patch.

It's my first ever CVE, so I'm pretty proud of it.

Links:

Top comments (2)

Collapse
 
rhymes profile image
rhymes

Thank you very much Stefan! Your CVE is deeply appreciated :-)

Collapse
 
cryptomance profile image
cryptomance

Thanks for your contribution to a safer world!

Billboard image

The Next Generation Developer Platform

Coherence is the first Platform-as-a-Service you can control. Unlike "black-box" platforms that are opinionated about the infra you can deploy, Coherence is powered by CNC, the open-source IaC framework, which offers limitless customization.

Learn more