apache / apache/answer-plugins
Patch CVE Vulnerability CVE-2025-22868 with Golang OAuth2 Dependency for All Connector Plugins
未关闭
- 主要语言
- Go
- 星标
- 131
- 派生
- 75
- PR 合并指标
- 30 天内没有已合并 PR
描述
For all connector plugins, roll the version of golang.org/x/oauth2 from 0.4.0 to version 0.27.0-1 or higher (latest available is 0.34.0).
CVE-2025-22868: An attacker can pass a malicious malformed token which causes unexpected memory to be consumed during parsing.
This CVE is rated high and should be patched immediately.
贡献指南
这个仓库没有索引到贡献指南
评估
这个 Issue 还没有评估数据。