Google LLC Vulnerabilities and Affected Products
Vulnerabilities associated with Google-oauth-java-client.
Products
Clear product- Asylo16 vulnerabilities
- Dart SDK4 vulnerabilities
- fscrypt3 vulnerabilities
- guest-oslogin3 vulnerabilities
- AWS S3 Crypto SDK for GoLang2 vulnerabilities
- Fuchsia2 vulnerabilities
- Fuchsia Kernel2 vulnerabilities
- libjxl2 vulnerabilities
- Android Play Core1 vulnerability
- Bazel1 vulnerability
- Bindiff1 vulnerability
- Brotli1 vulnerability
- Dart1 vulnerability
- Data-Transfer-Project1 vulnerability
- Drive for Desktop MacOS1 vulnerability
- Exposure Notifications Verification Server1 vulnerability
- Gerrit1 vulnerability
- go-attestation1 vulnerability
- Google Cloud IoT Device SDK for Embedded C1 vulnerability
- Google Earth Pro1 vulnerability
- Google Exposure-notifications-verification-server1 vulnerability
- Google Play Services SDK1 vulnerability
- Google-oauth-java-client1 vulnerability
- google-protobuf [JRuby Gem]1 vulnerability
- google/go-tpm library1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2021-22573HIGH | Incorrect signature verification on Google-oauth-java-clientThe vulnerability is that IDToken verifier does not verify if token is properly signed. Signature verification makes sure that the token's payload comes from valid provider, not from someone else. An attacker can provide a compromised token with custom payload. The token will pass the validation on the client side. We recommend upgrading to version 1.33.3 or above CWE-347May 3, 2022 | CVSS8.7v3.1 | EPSS0.296% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |