MEDIUM
Auth Bypass in Google's Closure-Library
Published Mar 26, 2020
6.5
MEDIUMCVSS 3.1
EPSS 0.54%
Description
A URL parsing issue in goog.uri of the Google Closure Library versions up to and including v20200224 allows an attacker to send malicious URLs to be parsed by the library and return the wrong authority. Mitigation: update your library to version v20200315.
Affected products
-
- Version v20200224StatusaffectedConstraints<=v20200224
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Closure-Library | n/a |
|
- < 20200315
No data.
No Red Hat product state for this CVE.
google-closure-library
npm
Introduced 0 Fixed 20200315.0.0
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | google-closure-library | 0 | 20200315.0.0 |
Remediation
No remediation recorded yet.
Weaknesses (2)
References (4)
- https://github.com/advisories/GHSA-vh5w-fg69-rc8m Advisory
- https://github.com/google/closure-library/commit/294fc00b01d248419d8f8de37580adf2a0024fc9 x_refsource_CONFIRMPatchThird Party Advisory
- https://github.com/google/closure-library/releases/tag/v20200315 x_refsource_CONFIRMThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-8910
| Link | Providers | Tags |
|---|---|---|
| https://github.com/advisories/GHSA-vh5w-fg69-rc8m | Advisory | |
| https://github.com/google/closure-library/commit/294fc00b01d248419d8f8de37580adf2a0024fc9 | x_refsource_CONFIRMPatchThird Party Advisory | |
| https://github.com/google/closure-library/releases/tag/v20200315 | x_refsource_CONFIRMThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2020-8910 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Google
Published Mar 26, 2020
Updated Aug 4, 2024
Reserved Feb 12, 2020
Link CVE-2020-8910
CISA Vulnrichment
GHSA-VH5W-FG69-RC8M Updated n/a