apache / apache/answer-plugins
Patch CVE Vulnerability CVE-2025-22868 with Golang OAuth2 Dependency for All Connector Plugins
未關閉
- 主要語言
- Go
- 星號
- 131
- 分支
- 75
- PR 合併指標
- 30 天內沒有已合併 PR
描述
For all connector plugins, roll the version of golang.org/x/oauth2 from 0.4.0 to version 0.27.0-1 or higher (latest available is 0.34.0).
CVE-2025-22868: An attacker can pass a malicious malformed token which causes unexpected memory to be consumed during parsing.
This CVE is rated high and should be patched immediately.
貢獻指南
這個儲存庫沒有索引到貢獻指南
評估
這個 Issue 還沒有評估資料。