[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2020-7692":6},{"stargazers_count":4,"fetched_at":5},7,"2026-06-05T08:55:32.481Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":20,"aliases":34,"duplicate_of":9,"upstream":36,"downstream":37,"duplicates":52,"related":53,"reserved_at":9,"published_at":54,"modified_at":55,"state":56,"summary":57,"references_raw":65,"kevs":119,"epss":120,"epss_history":123,"metrics":389,"affected":407},"CVE-2020-7692","PKCE support is not implemented in accordance with the RFC for OAuth 2.0 for Native Apps. Without the use of PKCE, the authorization code returned by an authorization server is not enough to guarantee that the client that issued the initial authorization request is the one that will be authorized. An attacker is able to obtain the authorization code using a malicious app on the client-side and use it to gain authorization to the protected resource. This affects the package com.google.oauth-client:google-oauth-client before 1.31.0.",null,[11],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":17,"likelihood_of_exploit":18,"capec":19},"CWE-863","Incorrect Authorization","The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.","weakness","Incomplete","Class","High",[],[21,30],{"_key":22,"name":23,"source":24,"url":25,"maturity":26,"reliability_score":27,"verified":28,"type":9,"platforms":29,"requires_auth":9,"exploitdb":9,"metasploit":9},"REF_0FC9968C3448655F","Exploit Reference (tools.ietf.org)","reference","https://tools.ietf.org/html/rfc8252%23section-8.1","unknown",0.2,false,[],{"_key":31,"name":23,"source":24,"url":32,"maturity":26,"reliability_score":27,"verified":28,"type":9,"platforms":33,"requires_auth":9,"exploitdb":9,"metasploit":9},"REF_7E36D9C983D4C272","https://tools.ietf.org/html/rfc7636%23section-1",[],[35],"GHSA-f263-c949-w85g",[],[38,40,42,44,46,48,50],{"_key":39},"DEBIAN-CVE-2020-7692",{"_key":41},"RHSA-2023:0560",{"_key":43},"RHSA-2023:0777",{"_key":45},"UBUNTU-CVE-2020-7692",{"_key":47},"RHSA-2023:3299",{"_key":49},"RHSA-2024:0778",{"_key":51},"RHSA-2023:6172",[],[],"2020-07-09T13:20:16.446Z","2024-09-17T03:47:55.563Z","Modified",{"cisa_kev":28,"cisa_ransomware":28,"cisa_vendor":9,"epss_severity":58,"epss_score":59,"severity":60,"severity_score":61,"severity_version":62,"severity_source":63,"severity_vector":64,"severity_status":56},"low",0.00091,"critical",9.1,"v3.1","nvd","CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",[66,75,79,84,88,91,97,101,106,111,115],{"url":67,"sources":68,"tags":71},"https://snyk.io/vuln/SNYK-JAVA-COMGOOGLEOAUTHCLIENT-575276",[69,63,70],"cve.org","osv_maven",[72,73,74],"X Refsource MISC","Third Party Advisory","WEB",{"url":76,"sources":77,"tags":78},"https://github.com/googleapis/google-oauth-java-client/issues/469",[69,63,70],[72,73,74],{"url":80,"sources":81,"tags":82},"https://github.com/googleapis/google-oauth-java-client/commit/13433cd7dd06267fc261f0b1d4764f8e3432c824",[69,63,70],[72,83,73,74],"Patch",{"url":25,"sources":85,"tags":86},[69,63,70],[72,87,73,74],"Exploit",{"url":32,"sources":89,"tags":90},[69,63,70],[72,87,73,74],{"url":92,"sources":93,"tags":94},"https://lists.apache.org/thread.html/r3db6ac73e0558d64f0b664f2fa4ef0a865e57c5de20f8321d3b48678%40%3Ccommits.druid.apache.org%3E",[69,63],[95,96],"Mailing List","X Refsource MLIST",{"url":98,"sources":99,"tags":100},"https://lists.apache.org/thread.html/reae8909b264d1103f321b9ce1623c10c1ddc77dba9790247f2c0c90f%40%3Ccommits.druid.apache.org%3E",[69,63],[95,96],{"url":102,"sources":103,"tags":104},"https://nvd.nist.gov/vuln/detail/CVE-2020-7692",[70],[105],"Advisory",{"url":107,"sources":108,"tags":109},"https://github.com/googleapis/google-oauth-java-client",[70],[110],"PACKAGE",{"url":112,"sources":113,"tags":114},"https://lists.apache.org/thread.html/r3db6ac73e0558d64f0b664f2fa4ef0a865e57c5de20f8321d3b48678@%3Ccommits.druid.apache.org%3E",[70],[74],{"url":116,"sources":117,"tags":118},"https://lists.apache.org/thread.html/reae8909b264d1103f321b9ce1623c10c1ddc77dba9790247f2c0c90f@%3Ccommits.druid.apache.org%3E",[70],[74],[],{"date":121,"score":59,"percentile":122},"2026-06-04",0.25659,[124,128,131,134,137,140,143,146,149,152,155,158,161,164,167,171,174,177,179,182,185,188,191,194,197,200,203,206,209,212,215,218,220,222,225,228,231,234,237,240,243,246,249,252,255,258,261,264,267,270,273,276,278,281,284,286,289,292,295,298,301,304,307,310,313,316,319,322,325,328,331,333,336,339,341,344,346,349,352,355,358,361,364,367,370,374,377,380,383,386],{"date":125,"score":126,"percentile":127},"2025-11-04",0.00099,0.28212,{"date":129,"score":126,"percentile":130},"2025-11-05",0.28189,{"date":132,"score":126,"percentile":133},"2025-11-06",0.28202,{"date":135,"score":126,"percentile":136},"2025-11-07",0.282,{"date":138,"score":126,"percentile":139},"2025-11-08",0.28203,{"date":141,"score":126,"percentile":142},"2025-11-09",0.28169,{"date":144,"score":126,"percentile":145},"2025-11-10",0.28146,{"date":147,"score":126,"percentile":148},"2025-11-11",0.28174,{"date":150,"score":126,"percentile":151},"2025-11-12",0.28225,{"date":153,"score":126,"percentile":154},"2025-11-13",0.28235,{"date":156,"score":126,"percentile":157},"2025-11-14",0.28227,{"date":159,"score":126,"percentile":160},"2025-11-15",0.28224,{"date":162,"score":126,"percentile":163},"2025-11-16",0.28192,{"date":165,"score":126,"percentile":166},"2025-11-17",0.28168,{"date":168,"score":169,"percentile":170},"2025-11-18",0.00384,0.56895,{"date":172,"score":169,"percentile":173},"2025-11-19",0.56912,{"date":175,"score":169,"percentile":176},"2025-11-20",0.56901,{"date":178,"score":126,"percentile":139},"2025-11-21",{"date":180,"score":126,"percentile":181},"2025-11-22",0.28216,{"date":183,"score":126,"percentile":184},"2025-11-23",0.28184,{"date":186,"score":126,"percentile":187},"2025-11-24",0.28158,{"date":189,"score":126,"percentile":190},"2025-11-25",0.28157,{"date":192,"score":126,"percentile":193},"2025-11-26",0.28156,{"date":195,"score":126,"percentile":196},"2025-11-27",0.28171,{"date":198,"score":126,"percentile":199},"2025-11-28",0.2814,{"date":201,"score":126,"percentile":202},"2025-11-29",0.28127,{"date":204,"score":126,"percentile":205},"2025-11-30",0.28104,{"date":207,"score":126,"percentile":208},"2025-12-01",0.2816,{"date":210,"score":126,"percentile":211},"2025-12-02",0.28182,{"date":213,"score":126,"percentile":214},"2025-12-03",0.2819,{"date":216,"score":126,"percentile":217},"2025-12-04",0.28125,{"date":219,"score":126,"percentile":190},"2025-12-05",{"date":221,"score":126,"percentile":193},"2025-12-06",{"date":223,"score":126,"percentile":224},"2025-12-07",0.28124,{"date":226,"score":126,"percentile":227},"2025-12-08",0.28138,{"date":229,"score":126,"percentile":230},"2025-12-09",0.28196,{"date":232,"score":126,"percentile":233},"2025-12-10",0.2827,{"date":235,"score":126,"percentile":236},"2025-12-11",0.28297,{"date":238,"score":126,"percentile":239},"2025-12-12",0.28311,{"date":241,"score":126,"percentile":242},"2025-12-13",0.28308,{"date":244,"score":126,"percentile":245},"2025-12-14",0.28275,{"date":247,"score":126,"percentile":248},"2025-12-15",0.28241,{"date":250,"score":126,"percentile":251},"2025-12-16",0.28255,{"date":253,"score":126,"percentile":254},"2025-12-17",0.28314,{"date":256,"score":126,"percentile":257},"2025-12-18",0.28363,{"date":259,"score":126,"percentile":260},"2025-12-19",0.28377,{"date":262,"score":126,"percentile":263},"2025-12-20",0.28341,{"date":265,"score":126,"percentile":266},"2025-12-21",0.28296,{"date":268,"score":126,"percentile":269},"2025-12-22",0.28262,{"date":271,"score":126,"percentile":272},"2025-12-23",0.28232,{"date":274,"score":126,"percentile":275},"2025-12-24",0.28239,{"date":277,"score":126,"percentile":254},"2025-12-25",{"date":279,"score":126,"percentile":280},"2025-12-26",0.28307,{"date":282,"score":126,"percentile":283},"2025-12-27",0.28304,{"date":285,"score":126,"percentile":157},"2025-12-28",{"date":287,"score":126,"percentile":288},"2025-12-29",0.28197,{"date":290,"score":126,"percentile":291},"2025-12-30",0.28194,{"date":293,"score":126,"percentile":294},"2025-12-31",0.28261,{"date":296,"score":126,"percentile":297},"2026-01-01",0.28373,{"date":299,"score":126,"percentile":300},"2026-01-02",0.28374,{"date":302,"score":126,"percentile":303},"2026-01-03",0.28354,{"date":305,"score":126,"percentile":306},"2026-01-04",0.28242,{"date":308,"score":126,"percentile":309},"2026-01-05",0.28234,{"date":311,"score":126,"percentile":312},"2026-01-06",0.28247,{"date":314,"score":126,"percentile":315},"2026-01-07",0.28273,{"date":317,"score":126,"percentile":318},"2026-01-08",0.28313,{"date":320,"score":126,"percentile":321},"2026-01-09",0.28303,{"date":323,"score":126,"percentile":324},"2026-01-10",0.28286,{"date":326,"score":126,"percentile":327},"2026-01-11",0.28268,{"date":329,"score":126,"percentile":330},"2026-01-12",0.28221,{"date":332,"score":126,"percentile":230},"2026-01-13",{"date":334,"score":126,"percentile":335},"2026-01-14",0.2824,{"date":337,"score":126,"percentile":338},"2026-01-15",0.28236,{"date":340,"score":126,"percentile":233},"2026-01-16",{"date":342,"score":126,"percentile":343},"2026-01-17",0.28274,{"date":345,"score":126,"percentile":330},"2026-01-18",{"date":347,"score":126,"percentile":348},"2026-01-19",0.28186,{"date":350,"score":126,"percentile":351},"2026-01-20",0.28172,{"date":353,"score":126,"percentile":354},"2026-01-21",0.28115,{"date":356,"score":126,"percentile":357},"2026-01-22",0.28089,{"date":359,"score":126,"percentile":360},"2026-01-23",0.28163,{"date":362,"score":126,"percentile":363},"2026-01-24",0.28153,{"date":365,"score":126,"percentile":366},"2026-01-25",0.28075,{"date":368,"score":126,"percentile":369},"2026-01-26",0.27987,{"date":371,"score":372,"percentile":373},"2026-01-27",0.00084,0.2463,{"date":375,"score":372,"percentile":376},"2026-01-28",0.24627,{"date":378,"score":372,"percentile":379},"2026-01-29",0.24585,{"date":381,"score":372,"percentile":382},"2026-01-30",0.24571,{"date":384,"score":372,"percentile":385},"2026-01-31",0.24564,{"date":387,"score":372,"percentile":388},"2026-02-01",0.24613,[390,397,405],{"source":69,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":391,"cvss_v4_0":9},{"baseScore":392,"baseSeverity":393,"vectorString":394,"impactScore":395,"exploitabilityScore":396},7.4,"HIGH","CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",8.7,5.6,{"source":63,"cvss_v2_0":398,"cvss_v3_0":9,"cvss_v3_1":403,"cvss_v4_0":9},{"baseScore":399,"baseSeverity":9,"vectorString":400,"impactScore":401,"exploitabilityScore":402},6.4,"AV:N/AC:L/Au:N/C:P/I:P/A:N",4.9,10,{"baseScore":61,"baseSeverity":404,"vectorString":64,"impactScore":395,"exploitabilityScore":402},"CRITICAL",{"source":70,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":406,"cvss_v4_0":9},{"baseScore":392,"baseSeverity":9,"vectorString":394,"impactScore":395,"exploitabilityScore":396},[408,420],{"ecosystem":9,"name":409,"vendor":410,"product":411,"cpe_part":412,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":413},"oauth client library for java","google","oauth_client_library_for_java","a",[414],{"version":415,"is_range":416,"range_type":417,"version_start":9,"version_start_type":9,"version_end":418,"version_end_type":419,"fixed_in":9},"lt1.31.0",true,"cpe","1.31.0","excluding",{"ecosystem":421,"name":422,"vendor":423,"product":424,"cpe_part":9,"purl_type":425,"purl_namespace":423,"purl_name":424,"source":9,"versions":426},"Maven","com.google.oauth-client:google-oauth-client","com.google.oauth-client","google-oauth-client","maven",[427],{"version":428,"is_range":416,"range_type":429,"version_start":9,"version_start_type":9,"version_end":418,"version_end_type":419,"fixed_in":9},"lt1_31_0","ecosystem"]