apache / apache/answer-plugins
Patch CVE Vulnerability CVE-2025-22868 with Golang OAuth2 Dependency for All Connector Plugins
Aperta
- Lingua principale
- Go
- Stelle
- 131
- Fork
- 75
- Metriche di merge delle PR
- Nessuna PR unita negli ultimi 30g
Descrizione
For all connector plugins, roll the version of golang.org/x/oauth2 from 0.4.0 to version 0.27.0-1 or higher (latest available is 0.34.0).
CVE-2025-22868: An attacker can pass a malicious malformed token which causes unexpected memory to be consumed during parsing.
This CVE is rated high and should be patched immediately.
Guida per i contributori
Nessuna guida per i contributori indicizzata per questo repository
Valutazione
Questa issue non è ancora stata valutata.