Логотип exploitDog
bind:CVE-2020-7692
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-7692

Количество 5

Количество 5

ubuntu логотип

CVE-2020-7692

больше 5 лет назад

PKCE support is not implemented in accordance with the RFC for OAuth 2.0 for Native Apps. Without the use of PKCE, the authorization code returned by an authorization server is not enough to guarantee that the client that issued the initial authorization request is the one that will be authorized. An attacker is able to obtain the authorization code using a malicious app on the client-side and use it to gain authorization to the protected resource. This affects the package com.google.oauth-client:google-oauth-client before 1.31.0.

CVSS3: 7.4
EPSS: Низкий
redhat логотип

CVE-2020-7692

больше 5 лет назад

PKCE support is not implemented in accordance with the RFC for OAuth 2.0 for Native Apps. Without the use of PKCE, the authorization code returned by an authorization server is not enough to guarantee that the client that issued the initial authorization request is the one that will be authorized. An attacker is able to obtain the authorization code using a malicious app on the client-side and use it to gain authorization to the protected resource. This affects the package com.google.oauth-client:google-oauth-client before 1.31.0.

CVSS3: 7.4
EPSS: Низкий
nvd логотип

CVE-2020-7692

больше 5 лет назад

PKCE support is not implemented in accordance with the RFC for OAuth 2.0 for Native Apps. Without the use of PKCE, the authorization code returned by an authorization server is not enough to guarantee that the client that issued the initial authorization request is the one that will be authorized. An attacker is able to obtain the authorization code using a malicious app on the client-side and use it to gain authorization to the protected resource. This affects the package com.google.oauth-client:google-oauth-client before 1.31.0.

CVSS3: 7.4
EPSS: Низкий
debian логотип

CVE-2020-7692

больше 5 лет назад

PKCE support is not implemented in accordance with the RFC for OAuth 2 ...

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-f263-c949-w85g

больше 4 лет назад

Improper Authorization in Google OAuth Client

CVSS3: 7.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2020-7692

PKCE support is not implemented in accordance with the RFC for OAuth 2.0 for Native Apps. Without the use of PKCE, the authorization code returned by an authorization server is not enough to guarantee that the client that issued the initial authorization request is the one that will be authorized. An attacker is able to obtain the authorization code using a malicious app on the client-side and use it to gain authorization to the protected resource. This affects the package com.google.oauth-client:google-oauth-client before 1.31.0.

CVSS3: 7.4
0%
Низкий
больше 5 лет назад
redhat логотип
CVE-2020-7692

PKCE support is not implemented in accordance with the RFC for OAuth 2.0 for Native Apps. Without the use of PKCE, the authorization code returned by an authorization server is not enough to guarantee that the client that issued the initial authorization request is the one that will be authorized. An attacker is able to obtain the authorization code using a malicious app on the client-side and use it to gain authorization to the protected resource. This affects the package com.google.oauth-client:google-oauth-client before 1.31.0.

CVSS3: 7.4
0%
Низкий
больше 5 лет назад
nvd логотип
CVE-2020-7692

PKCE support is not implemented in accordance with the RFC for OAuth 2.0 for Native Apps. Without the use of PKCE, the authorization code returned by an authorization server is not enough to guarantee that the client that issued the initial authorization request is the one that will be authorized. An attacker is able to obtain the authorization code using a malicious app on the client-side and use it to gain authorization to the protected resource. This affects the package com.google.oauth-client:google-oauth-client before 1.31.0.

CVSS3: 7.4
0%
Низкий
больше 5 лет назад
debian логотип
CVE-2020-7692

PKCE support is not implemented in accordance with the RFC for OAuth 2 ...

CVSS3: 7.4
0%
Низкий
больше 5 лет назад
github логотип
GHSA-f263-c949-w85g

Improper Authorization in Google OAuth Client

CVSS3: 7.4
0%
Низкий
больше 4 лет назад

Уязвимостей на страницу