Improper Authorization
Published Jul 9, 2020
9.1
CRITICALCVSS 3.1
EPSS 1.59%
Description
PKCE support is not implemented in accordance with the RFC for OAuth 2.0 for Native Apps. Without the use of PKCE, the authorization code returned by an authorization server is not enough to guarantee that the client that issued the initial authorization request is the one that will be authorized. An attacker is able to obtain the authorization code using a malicious app on the client-side and use it to gain authorization to the protected resource. This affects the package com.google.oauth-client:google-oauth-client before 1.31.0.
Affected products
- Vendor n/a Product Com.google.oauth-Client:google-Oauth-Client Defaultn/a
- Version unspecifiedStatusaffectedConstraints<1.31.0
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Com.google.oauth-Client:google-Oauth-Client | n/a |
|
- < 1.31.0
No data.
OCP-Tools-4.12-RHEL-8
jenkins-2-plugins-0:4.12.1698294000-1.el8
Fixed · RHSA-2023:6172
OCP-Tools-4.12-RHEL-8
jenkins-2-plugins-0:4.12.1706515741-1.el8
Fixed · RHSA-2024:0778
OCP-Tools-4.13-RHEL-8
jenkins-2-plugins-0:4.13.1684911916-1.el8
Fixed · RHSA-2023:3299
Red Hat OpenShift Container Platform 4.10
jenkins-2-plugins-0:4.10.1675144701-1.el8
Fixed · RHSA-2023:0560
Red Hat OpenShift Container Platform 4.9
jenkins-2-plugins-0:4.9.1675668922-1.el8
Fixed · RHSA-2023:0777
Logging Subsystem for Red Hat OpenShift
openshift-logging/elasticsearch6-rhel8
Not affected
Red Hat Fuse 7
google-oauth-client
Fix deferred
Red Hat JBoss Fuse 6
google-oauth-client
Out of support scope
Red Hat OpenShift Container Platform 3.11
jenkins-2-plugins
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| OCP-Tools-4.12-RHEL-8 | jenkins-2-plugins-0:4.12.1698294000-1.el8 | Fixed | RHSA-2023:6172 |
| OCP-Tools-4.12-RHEL-8 | jenkins-2-plugins-0:4.12.1706515741-1.el8 | Fixed | RHSA-2024:0778 |
| OCP-Tools-4.13-RHEL-8 | jenkins-2-plugins-0:4.13.1684911916-1.el8 | Fixed | RHSA-2023:3299 |
| Red Hat OpenShift Container Platform 4.10 | jenkins-2-plugins-0:4.10.1675144701-1.el8 | Fixed | RHSA-2023:0560 |
| Red Hat OpenShift Container Platform 4.9 | jenkins-2-plugins-0:4.9.1675668922-1.el8 | Fixed | RHSA-2023:0777 |
| Logging Subsystem for Red Hat OpenShift | openshift-logging/elasticsearch6-rhel8 | Not affected | n/a |
| Red Hat Fuse 7 | google-oauth-client | Fix deferred | n/a |
| Red Hat JBoss Fuse 6 | google-oauth-client | Out of support scope | n/a |
| Red Hat OpenShift Container Platform 3.11 | jenkins-2-plugins | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
1 other source (GHSA) ▾
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:P/I:P/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Table of values (18 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 1.59% (0.01587) | 74.76th | v5 (v2026.06.15) |
| Sep 20, 2026 | 1.59% (0.01587) | 74.51th | v5 (v2026.06.15) |
| Jul 20, 2024 | 0.67% (0.00666) | 79.93th | v3 (v2023.03.01) |
| Jun 15, 2024 | 0.67% (0.00666) | 79.79th | v3 (v2023.03.01) |
| May 30, 2024 | 0.58% (0.00583) | 78.08th | v3 (v2023.03.01) |
| Mar 26, 2024 | 0.43% (0.00428) | 73.93th | v3 (v2023.03.01) |
| Feb 21, 2024 | 0.37% (0.00370) | 71.89th | v3 (v2023.03.01) |
| Feb 8, 2024 | 0.43% (0.00429) | 73.74th | v3 (v2023.03.01) |
| Nov 8, 2023 | 0.43% (0.00429) | 71.53th | v3 (v2023.03.01) |
| Sep 3, 2023 | 0.23% (0.00231) | 60.61th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.24% (0.00239) | 60.11th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.11% (0.01108) | 55.18th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.11% (0.01108) | 51.54th | v2 (v2022.01.01) |
| Feb 4, 2022 | 17.91% (0.17909) | 93.39th | v2 (v2022.01.01) |
| Feb 3, 2022 | 3.02% (0.03019) | 64.98th | v1 |
| Jan 6, 2022 | 3.02% (0.03019) | 64.65th | v1 |
| Jan 5, 2022 | 0.69% (0.00689) | 48.95th | v5 (v2026.06.15) |
| Apr 14, 2021 | 0.69% (0.00689) | 0.00th | v1 |
References (14)
- https://access.redhat.com/security/cve/CVE-2020-7692 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1856376 Issue Tracking
- https://github.com/advisories/GHSA-f263-c949-w85g Advisory
- https://github.com/googleapis/google-oauth-java-client/commit/13433cd7dd06267fc261f0b1d4764f8e3432c824 x_refsource_MISCPatchThird Party Advisory
- https://github.com/googleapis/google-oauth-java-client/issues/469 x_refsource_MISCThird Party Advisory
- https://lists.apache.org/thread.html/r3db6ac73e0558d64f0b664f2fa4ef0a865e57c5de20f8321d3b48678%40%3Ccommits.druid.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r3db6ac73e0558d64f0b664f2fa4ef0a865e57c5de20f8321d3b48678@%3Ccommits.druid.apache.org%3E
- https://lists.apache.org/thread.html/reae8909b264d1103f321b9ce1623c10c1ddc77dba9790247f2c0c90f%40%3Ccommits.druid.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/reae8909b264d1103f321b9ce1623c10c1ddc77dba9790247f2c0c90f@%3Ccommits.druid.apache.org%3E
- https://nvd.nist.gov/vuln/detail/CVE-2020-7692
- https://snyk.io/vuln/SNYK-JAVA-COMGOOGLEOAUTHCLIENT-575276 x_refsource_MISCThird Party Advisory
- https://tools.ietf.org/html/rfc7636%23section-1 x_refsource_MISCExploitThird Party Advisory
- https://tools.ietf.org/html/rfc8252%23section-8.1 x_refsource_MISCExploitThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2020-7692
Change history (0)
No recorded changes yet.