{"id":"GHSA-7543-mr7h-6v86","aliases":[],"url":"https://o3.security/vulnerability/GHSA-7543-mr7h-6v86","summary":"Improper Authorization in googleapis","details":"Versions of `googleapis` prior to 39.1.0 are vulnerable to Improper Authorization. Setting credentials to one client may apply to all clients which may cause requests to be sent with the incorrect credentials.\n\n\n## Recommendation\n\nUpgrade to version 39.1.0.","published":"2020-09-02T16:00:26Z","modified":"2021-09-27T16:15:52Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"googleapis","fixedVersion":"39.1.0"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/googleapis/google-api-nodejs-client/issues/1594"},{"type":"PACKAGE","url":"https://github.com/googleapis/google-api-nodejs-client"},{"type":"WEB","url":"https://www.npmjs.com/advisories/791"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2021-09-27T16:15:52Z"}}