• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
high severity bug reported in google's oauth client library for java

High-Severity Bug Reported in Google’s OAuth Client Library for Java

You are here: Home / General Cyber Security News / High-Severity Bug Reported in Google’s OAuth Client Library for Java
May 19, 2022

Google final thirty day period resolved a superior-severity flaw in its OAuth customer library for Java that could be abused by a destructive actor with a compromised token to deploy arbitrary payloads.

Tracked as CVE-2021-22573, the vulnerability is rated 8.7 out of 10 for severity and relates to an authentication bypass in the library that stems from an incorrect verification of the cryptographic signature.

Credited with exploring and reporting the flaw on March 12 is Tamjid Al Rahat, a fourth-yr Ph.D. student of Personal computer Science at the University of Virginia, who has been awarded $5,000 as part of Google’s bug bounty application.

✔ Approved Seller From Our Partners
Mullvad VPN Discount

Protect your privacy by Mullvad VPN. Mullvad VPN is one of the famous brands in the security and privacy world. With Mullvad VPN you will not even be asked for your email address. No log policy, no data from you will be saved. Get your license key now from the official distributor of Mullvad with discount: SerialCart® (Limited Offer).

➤ Get Mullvad VPN with 12% Discount


“The vulnerability is that the IDToken verifier does not verify if the token is correctly signed,” an advisory for the flaw reads.

“Signature verification helps make positive that the token’s payload will come from a valid provider, not from another person else. An attacker can offer a compromised token with custom made payload. The token will go the validation on the customer facet.”

The open-source Java library, developed on the Google HTTP Client Library for Java, tends to make it feasible to obtain accessibility tokens to any services on the web that supports the OAuth authorization standard.

CyberSecurity

Google, in its README file for the job on GitHub, notes that the library is supported in routine maintenance method and that it really is only correcting important bugs, indicative of the severity of the vulnerability.

Customers of the google-oauth-java-consumer library are suggested to update to version 1.33.3, introduced on April 13, to mitigate any probable risk.

Identified this posting exciting? Follow THN on Fb, Twitter  and LinkedIn to browse extra exclusive written content we write-up.


Some components of this post are sourced from:
thehackernews.com

Previous Post: «Cyber Security News Bad Bots Swarm the Internet in Record Numbers in 2021
Next Post: US security agency issues emergency alert over vulnerable VMware products us security agency issues emergency alert over vulnerable vmware products»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails
  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]

Copyright © TheCyberSecurity.News, All Rights Reserved.