Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-22868

Опубликовано: 26 фев. 2025
Источник: debian
EPSS Низкий

Описание

An attacker can pass a malicious malformed token which causes unexpected memory to be consumed during parsing.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
golang-golang-x-oauth2fixed0.27.0-1package
golang-golang-x-oauth2no-dsabookwormpackage
golang-golang-x-oauth2ignoredbullseyepackage

Примечания

  • https://pkg.go.dev/vuln/GO-2025-3488

  • https://go-review.googlesource.com/c/oauth2/+/652155

  • https://github.com/golang/go/issues/71490

EPSS

Процентиль: 23%
0.00076
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
5 месяцев назад

An attacker can pass a malicious malformed token which causes unexpected memory to be consumed during parsing.

CVSS3: 7.5
redhat
5 месяцев назад

An attacker can pass a malicious malformed token which causes unexpected memory to be consumed during parsing.

CVSS3: 7.5
nvd
5 месяцев назад

An attacker can pass a malicious malformed token which causes unexpected memory to be consumed during parsing.

CVSS3: 7.5
msrc
5 месяцев назад

Описание отсутствует

suse-cvrf
5 месяцев назад

Security update for restic

EPSS

Процентиль: 23%
0.00076
Низкий