[Git][security-tracker-team/security-tracker][master] Track fixed version for CVE-2020-7692/google-oauth-client-java via unstable

Salvatore Bonaccorso (@carnil) carnil at debian.org
Mon May 31 05:18:44 BST 2021



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
7cbfdf59 by Salvatore Bonaccorso at 2021-05-31T06:17:52+02:00
Track fixed version for CVE-2020-7692/google-oauth-client-java via unstable

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -93700,7 +93700,7 @@ CVE-2020-7694 (This affects all versions of package uvicorn. The request logger
 CVE-2020-7693 (Incorrect handling of Upgrade header with the value websocket leads in ...)
 	- node-socks <itp> (bug #922921)
 CVE-2020-7692 (PKCE support is not implemented in accordance with the RFC for OAuth 2 ...)
-	- google-oauth-client-java <unfixed> (bug #988944)
+	- google-oauth-client-java 1.28.0-2 (bug #988944)
 	NOTE: https://snyk.io/vuln/SNYK-JAVA-COMGOOGLEOAUTHCLIENT-575276
 	NOTE: https://github.com/googleapis/google-oauth-java-client/issues/469
 	NOTE: https://github.com/googleapis/google-oauth-java-client/commit/13433cd7dd06267fc261f0b1d4764f8e3432c824



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7cbfdf599dbeb0508154472ea587c80c9ff9ae55

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7cbfdf599dbeb0508154472ea587c80c9ff9ae55
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20210531/5e48e1f1/attachment.htm>


More information about the debian-security-tracker-commits mailing list