Improper Verification of Cryptographic Signature in Google API Client Library for Java - CVE-2021-22573

 

Improper Verification of Cryptographic Signature in Google API Client Library for Java - CVE-2021-22573

Published: June 17, 2022


Vulnerability identifier: #VU64471
CSH Severity: Low
CVSS v4: 8.4 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-22573
CWE-ID: CWE-347
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to gain access to sensitive information.

The vulnerability exists due to IDToken verifier does not verify if token is properly signed. A remote authenticated user can provide a compromised token with custom payload and gain access to sensitive information.


Affected software

Google API Client Library for Java
IBM Qradar SIEM
Fuse
Oracle Middleware Common Libraries and Tools
Autodesk Infraworks
IBM Maximo Asset Management
IBM Maximo Application Suite
openSUSE Leap
openEuler
google-oauth-java-client-help
google-oauth-java-client
google-oauth-java-client-servlet
google-oauth-java-client-parent
google-oauth-java-client-java6
google-oauth-java-client-javadoc
watsonx.data
Red Hat Camel for Spring Boot

How to mitigate CVE-2021-22573

Install updates from vendor's website.

Google API Client Library for Java - update to 1.33.3
Fuse - update to 7.10.2-P1
Autodesk Infraworks - addressed in versions 2021.2 Hotfix 9, 2023.1 Hotfix 1
google-oauth-java-client-help - update to 1.22.0-6
google-oauth-java-client - update to 1.22.0-6
google-oauth-java-client-servlet - update to 1.22.0-150200.3.7.1
google-oauth-java-client-parent - update to 1.22.0-150200.3.7.1
google-oauth-java-client - update to 1.22.0-150200.3.7.1
google-oauth-java-client-java6 - update to 1.22.0-150200.3.7.1
google-oauth-java-client-javadoc - update to 1.22.0-150200.3.7.1
watsonx.data - update to 2.0.2
Red Hat Camel for Spring Boot - update to 3.14.5
IBM Maximo Asset Management - addressed in versions 7.6.1.2.39, 7.6.1.3.13
IBM Maximo Application Suite - update to 8.6.7

External References

Related Security Bulletins