In ORY Fosite (the security first OAuth2 & OpenID Connect framework for Go) before version 0.34.0, the `TokenRevocationHandler` ignores errors coming from the storage. This can lead to unexpected 200 status codes indicating successful revocation while the token is still valid. Whether an attacker can use this for her advantage depends on the ability to trigger errors in the store. This is fixed in version 0.34.0
Cite this page
CVE-2020-15223. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2020-15223
Use CWE-755, Ory vendor hub and Fosite product page to widen CVE-2020-15223 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2020-15222, CVE-2020-15234 and CVE-2020-15233 for nearby disclosures in the same product family.