[Git][security-tracker-team/security-tracker][master] Track fixed version for CVE-2020-7692/google-oauth-client-java via unstable
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Mon May 31 05:18:44 BST 2021
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
7cbfdf59 by Salvatore Bonaccorso at 2021-05-31T06:17:52+02:00
Track fixed version for CVE-2020-7692/google-oauth-client-java via unstable
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -93700,7 +93700,7 @@ CVE-2020-7694 (This affects all versions of package uvicorn. The request logger
CVE-2020-7693 (Incorrect handling of Upgrade header with the value websocket leads in ...)
- node-socks <itp> (bug #922921)
CVE-2020-7692 (PKCE support is not implemented in accordance with the RFC for OAuth 2 ...)
- - google-oauth-client-java <unfixed> (bug #988944)
+ - google-oauth-client-java 1.28.0-2 (bug #988944)
NOTE: https://snyk.io/vuln/SNYK-JAVA-COMGOOGLEOAUTHCLIENT-575276
NOTE: https://github.com/googleapis/google-oauth-java-client/issues/469
NOTE: https://github.com/googleapis/google-oauth-java-client/commit/13433cd7dd06267fc261f0b1d4764f8e3432c824
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7cbfdf599dbeb0508154472ea587c80c9ff9ae55
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7cbfdf599dbeb0508154472ea587c80c9ff9ae55
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20210531/5e48e1f1/attachment.htm>
More information about the debian-security-tracker-commits
mailing list