google / google/apitools

apitools depends on oauth2client which is archived and insecure

Open
#330 1 comment 0 reactions 0 assignees View on GitHub
Dominant language
Python
Stars
157
Forks
131
PR merge metrics
No merged PRs in 30d

Description

apitools uses the archived dependency https://github.com/googleapis/oauth2client

oauth2client vendors pycrypto 2.6, which is an unmaintained project and contains [CVE-2018-6594](https://github.com/pghmcfc/pycrypto/commit/2f6c124e127b5dd98723e7e75a9825c4ed8bd5c7) (note, 2.6 was published on May 24, 2012). oauth2client will not receive upstream security fixes.

Is apitools transitively affected by CVE-2018-6594? Could apitools deprecate use of oauth2client?

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.