[go: nahoru, domu]

Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security vulnerabilities in google-http-client-1.38.0 #1207

Closed
clausfod opened this issue Dec 19, 2020 · 1 comment
Closed

Security vulnerabilities in google-http-client-1.38.0 #1207

clausfod opened this issue Dec 19, 2020 · 1 comment
Assignees
Labels
triage me I really want to be triaged.

Comments

@clausfod
Copy link

[INFO] - com.google.http-client:google-http-client:jar:1.38.0:runtime
[INFO] - io.opencensus:opencensus-api:jar:0.24.0:runtime
[INFO] - io.grpc:grpc-context:jar:1.22.1:runtime

Please update OpenCensus to a newer version:
Filename: grpc-context-1.22.1.jar | Highest CVSS Score: 7.5 | Amount of CVSS: 1 | References: CVE-2020-7768 (7.5)

[INFO] - com.google.guava:guava:jar:30.0-android:runtime
[INFO] +- com.google.guava:failureaccess:jar:1.0.1:runtime
[INFO] - com.google.guava:listenablefuture:jar:9999.0-empty-to-avoid-conflict-with-guava:runtime

Please update Guava to a newer version:
Filename: failureaccess-1.0.1.jar | Highest CVSS Score: 3.3 | Amount of CVSS: 1 | References: CVE-2020-8908 (3.3)

Please look into this:
Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution.
Filename: google-http-client-1.38.0.jar | Highest CVSS Score: 5.3 | Amount of CVSS: 1 | References: CVE-2020-13956 (5.3)

@yoshi-automation yoshi-automation added the triage me I really want to be triaged. label Dec 20, 2020
@elharo
Copy link
Contributor
elharo commented Dec 21, 2020

The OpenCensus report is invalid.
Guava is already updated.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
triage me I really want to be triaged.
Projects
None yet
Development

No branches or pull requests

3 participants