Skip to content

Security vulnerability CVE-2020-29582 #685

@pdodds

Description

@pdodds

Checklist

  • I have looked into the Readme and Examples, and have not found a suitable solution or answer.
  • I have looked into the API documentation and have not found a suitable solution or answer.
  • I have searched the issues and have not found a suitable solution or answer.
  • I have searched the Auth0 Community forums and have not found a suitable solution or answer.
  • I agree to the terms within the Auth0 Code of Conduct.

Description

We are currently tracking an issue based on the use of Auth0 in a Java application - see https://nvd.nist.gov/vuln/detail/cve-2020-29582

Are you planning to resolve the dependency version, I assume this might be linked to changing the OKHttp version?

Reproduction

  • Add Auth0 as dependency in Maven

Additional context

No response

auth0-java version

2.15

Java version

21

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugThis points to a verified bug in the code

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions