CVE-2023-34246 - How Doorkeeper's Public Client Consent Flaw Exposed OAuth in Rails Apps
If you use Doorkeeper to handle OAuth 2 authentication in your Ruby on Rails or Grape APIs, you need to know about a major vulnerability