PyPi: Glocaltokens

CVE-2022-23491

Transitive

Safety vulnerability ID: 71462

This vulnerability was reviewed by experts

The information on this page was manually curated by our Cybersecurity Intelligence Team.

Created at Dec 07, 2022 Updated at Nov 29, 2024
Scan your Python projects for vulnerabilities →

Advisory

Glocaltokens version 0.7.1 updates its certifi dependency from version 2021.10.8 to 2022.12.7 to address the security vulnerability identified as CVE-2022-23491.

Affected package

glocaltokens

Latest version: 0.7.3

Tool to extract Google device local authentication tokens in Python

Affected versions

Fixed versions

Vulnerability changelog

Changes

- Bump zeroconf from 0.53.0 to 0.115.1 dependabot (447)

🐛 Bug Fixes

- Censor password better KapJI (470)

📄 Documentation

- Bump codespell from 2.2.4 to 2.2.6 dependabot (449)

🔧 Internal structure enhancement

- Bump crazy-max/ghaction-github-labeler from 4.2.0 to 5.0.0 dependabot (434)
- Bump actions/checkout from 3 to 4 dependabot (427)
- Bump crazy-max/ghaction-github-labeler from 4.1.0 to 4.2.0 dependabot (423)

🧱 Dependency Updates

- Require gpsoauth^1.1.1 KapJI (534)
- Bump gpsoauth from 1.1.0 to 1.1.1 dependabot (533)
- Bump pylint from 3.2.2 to 3.2.3 dependabot (532)
- Bump grpcio from 1.64.0 to 1.64.1 dependabot (530)
- Bump requests from 2.32.2 to 2.32.3 dependabot (529)
- Bump codespell from 2.2.6 to 2.3.0 dependabot (528)
- Bump requests from 2.32.1 to 2.32.2 dependabot (527)
- Bump requests from 2.31.0 to 2.32.1 dependabot (526)
- Bump grpcio from 1.63.0 to 1.64.0 dependabot (525)
- Bump pylint from 3.2.0 to 3.2.2 dependabot (524)
- Bump pylint from 3.1.0 to 3.2.0 dependabot (523)
- Bump pre-commit from 3.7.0 to 3.7.1 dependabot (522)
- Bump grpcio from 1.62.2 to 1.63.0 dependabot (520)
- Bump mypy from 1.9.0 to 1.10.0 dependabot (519)
- Bump grpcio from 1.62.1 to 1.62.2 dependabot (518)
- Bump types-protobuf from 4.25.0.20240410 to 4.25.0.20240417 dependabot (517)
- Bump zeroconf from 0.132.0 to 0.132.2 dependabot (516)
- Bump gpsoauth from 1.0.4 to 1.1.0 dependabot (515)
- Bump types-protobuf from 4.24.0.20240408 to 4.25.0.20240410 dependabot (514)
- Bump types-protobuf from 4.24.0.20240311 to 4.24.0.20240408 dependabot (513)
- Bump zeroconf from 0.131.0 to 0.132.0 dependabot (512)
- Bump pre-commit from 3.6.2 to 3.7.0 dependabot (510)
- Bump grpcio from 1.62.0 to 1.62.1 dependabot (509)
- Bump types-protobuf from 4.24.0.20240302 to 4.24.0.20240311 dependabot (508)
- Bump mypy from 1.8.0 to 1.9.0 dependabot (507)
- Bump types-protobuf from 4.24.0.20240129 to 4.24.0.20240302 dependabot (505)
- Bump pylint from 3.0.3 to 3.1.0 dependabot (504)
- Bump grpcio from 1.60.1 to 1.62.0 dependabot (503)
- Bump pre-commit from 3.6.1 to 3.6.2 dependabot (502)
- Bump pre-commit from 3.6.0 to 3.6.1 dependabot (501)
- Bump release-drafter/release-drafter from 5 to 6 dependabot (500)
- Bump grpcio from 1.60.0 to 1.60.1 dependabot (499)
- Bump types-protobuf from 4.24.0.20240106 to 4.24.0.20240129 dependabot (498)
- Bump abatilo/actions-poetry from 2.4.0 to 3.0.0 dependabot (497)
- Bump types-protobuf from 4.24.0.4 to 4.24.0.20240106 dependabot (496)
- Bump pytest from 7.4.3 to 7.4.4 dependabot (495)
- Bump abatilo/actions-poetry from 2.3.0 to 2.4.0 dependabot (494)
- Bump grpc-stubs from 1.53.0.4 to 1.53.0.5 dependabot (493)
- Bump grpc-stubs from 1.53.0.3 to 1.53.0.4 dependabot (492)
- Bump black from 23.12.0 to 23.12.1 dependabot (491)
- Bump mypy from 1.7.1 to 1.8.0 dependabot (490)
- Bump zeroconf from 0.130.0 to 0.131.0 dependabot (489)
- Bump zeroconf from 0.129.0 to 0.130.0 dependabot (488)
- Bump isort from 5.13.1 to 5.13.2 dependabot (487)
- Bump zeroconf from 0.128.4 to 0.129.0 dependabot (486)
- Bump black from 23.11.0 to 23.12.0 dependabot (485)
- Bump isort from 5.13.0 to 5.13.1 dependabot (484)
- Bump pylint from 3.0.2 to 3.0.3 dependabot (483)
- Bump zeroconf from 0.128.0 to 0.128.4 dependabot (482)
- Bump pre-commit from 3.5.0 to 3.6.0 dependabot (481)
- Bump isort from 5.12.0 to 5.13.0 dependabot (480)
- Bump grpcio from 1.59.3 to 1.60.0 dependabot (479)
- Bump actions/setup-python from 4 to 5 dependabot (478)
- Bump zeroconf from 0.127.0 to 0.128.0 dependabot (477)
- Bump flake8-bugbear from 23.11.28 to 23.12.2 dependabot (476)
- Bump flake8-bugbear from 23.11.26 to 23.11.28 dependabot (475)
- Bump gpsoauth from 1.0.3 to 1.0.4 dependabot (474)
- Bump flake8-bugbear from 23.9.16 to 23.11.26 dependabot (473)
- Bump mypy from 1.7.0 to 1.7.1 dependabot (472)
- Bump gpsoauth from 1.0.2 to 1.0.3 dependabot (471)
- Update dev dependencies KapJI (469)
- Bump grpcio from 1.59.2 to 1.59.3 dependabot (468)
- Bump zeroconf from 0.126.0 to 0.127.0 dependabot (467)
- Bump zeroconf from 0.125.0 to 0.126.0 dependabot (466)
- Bump zeroconf from 0.122.3 to 0.125.0 dependabot (465)
- Bump zeroconf from 0.122.2 to 0.122.3 dependabot (464)
- Bump zeroconf from 0.120.0 to 0.122.2 dependabot (463)
- Bump black from 23.10.1 to 23.11.0 dependabot (462)
- Bump zeroconf from 0.115.1 to 0.120.0 dependabot (461)
- Bump urllib3 from 1.26.8 to 1.26.18 dependabot (460)
- Bump certifi from 2022.12.7 to 2023.7.22 dependabot (459)
- Bump pygments from 2.11.2 to 2.16.1 dependabot (458)
- Bump codespell from 2.2.4 to 2.2.6 dependabot (449)
- Bump grpcio from 1.59.0 to 1.59.2 dependabot (457)
- Bump types-protobuf from 4.24.0.3 to 4.24.0.4 dependabot (456)
- Bump pytest from 7.4.2 to 7.4.3 dependabot (455)
- Bump black from 23.10.0 to 23.10.1 dependabot (454)
- Bump types-protobuf from 4.24.0.2 to 4.24.0.3 dependabot (453)
- Bump black from 23.9.1 to 23.10.0 dependabot (452)
- Bump pre-commit from 3.4.0 to 3.5.0 dependabot (451)
- Bump simplejson from 3.19.1 to 3.19.2 dependabot (450)
- Bump pylint from 2.17.6 to 2.17.7 dependabot (448)
- Bump grpcio from 1.58.0 to 1.59.0 dependabot (446)
- Bump grpc-stubs from 1.53.0.2 to 1.53.0.3 dependabot (445)
- Bump gpsoauth from 1.0.2 to 1.0.3 dependabot (442)
- Bump pylint from 2.17.5 to 2.17.6 dependabot (441)
- Bump types-protobuf from 4.24.0.1 to 4.24.0.2 dependabot (440)
- Bump requests from 2.30.0 to 2.31.0 dependabot (439)
- Bump flake8-bugbear from 23.7.10 to 23.9.16 dependabot (438)
- Bump black from 23.7.0 to 23.9.1 dependabot (433)
- Bump pytest from 7.4.1 to 7.4.2 dependabot (431)
- Bump grpcio from 1.57.0 to 1.58.0 dependabot (430)
- Bump pre-commit from 3.3.3 to 3.4.0 dependabot (425)
- Bump pytest from 7.3.1 to 7.4.1 dependabot (424)
- Bump types-protobuf from 4.24.0.0 to 4.24.0.1 dependabot (417)
- Bump grpcio from 1.56.2 to 1.57.0 dependabot (415)
- Bump types-protobuf from 4.23.0.3 to 4.24.0.0 dependabot (414)
- Bump flake8 from 6.0.0 to 6.1.0 dependabot (409)
- Bump types-protobuf from 4.23.0.2 to 4.23.0.3 dependabot (413)
- Bump pylint from 2.17.4 to 2.17.5 dependabot (408)
- Bump types-protobuf from 4.23.0.1 to 4.23.0.2 dependabot (406)
- Bump grpcio from 1.56.0 to 1.56.2 dependabot (404)
- Bump flake8-bugbear from 23.6.5 to 23.7.10 dependabot (403)
- Bump black from 23.3.0 to 23.7.0 dependabot (402)
- Bump flake8-comprehensions from 3.12.0 to 3.14.0 dependabot (401)
- Bump grpcio from 1.54.0 to 1.56.0 dependabot (397)
- Bump pre-commit from 3.3.2 to 3.3.3 dependabot (393)
- Bump pre-commit from 3.3.1 to 3.3.2 dependabot (387)
- Bump flake8-bugbear from 23.5.9 to 23.6.5 dependabot (390)
- Bump types-protobuf from 4.23.0.0 to 4.23.0.1 dependabot (385)
- Bump flake8-bugbear from 23.3.23 to 23.5.9 dependabot (384)
- Bump types-protobuf from 4.22.0.2 to 4.23.0.0 dependabot (382)
- Bump pylint from 2.17.3 to 2.17.4 dependabot (381)
- Bump requests from 2.29.0 to 2.30.0 dependabot (380)
- Bump pre-commit from 3.3.0 to 3.3.1 dependabot (379)
- Bump pre-commit from 3.2.2 to 3.3.0 dependabot (378)
- Bump grpc-stubs from 1.53.0.1 to 1.53.0.2 dependabot (377)
- Bump requests from 2.28.2 to 2.29.0 dependabot (376)
- Bump pylint from 2.17.2 to 2.17.3 dependabot (375)
- Bump grpcio from 1.53.0 to 1.54.0 dependabot (374)
- Bump pytest from 7.3.0 to 7.3.1 dependabot (373)
- Bump flake8-comprehensions from 3.11.1 to 3.12.0 dependabot (372)
- Bump pytest from 7.2.2 to 7.3.0 dependabot (370)
- Bump grpc-stubs from 1.24.12.1 to 1.53.0.1 dependabot (368)
- Bump simplejson from 3.18.4 to 3.19.1 dependabot (367)
- Bump types-protobuf from 4.22.0.1 to 4.22.0.2 dependabot (366)
- Bump pre-commit from 3.2.1 to 3.2.2 dependabot (365)
- Bump zeroconf from 0.47.4 to 0.53.0 dependabot (363)
- Bump pylint from 2.17.1 to 2.17.2 dependabot (362)
- Bump types-protobuf from 4.22.0.0 to 4.22.0.1 dependabot (361)
- Bump black from 23.1.0 to 23.3.0 dependabot (360)
- Bump grpcio from 1.51.3 to 1.53.0 dependabot (359)
- Bump pre-commit from 3.2.0 to 3.2.1 dependabot (358)
- Bump flake8-bugbear from 23.3.12 to 23.3.23 dependabot (357)
- Bump pylint from 2.17.0 to 2.17.1 dependabot (356)
- Bump flake8-comprehensions from 3.11.0 to 3.11.1 dependabot (355)
- Bump zeroconf from 0.47.3 to 0.47.4 dependabot (354)
- Bump pre-commit from 3.1.1 to 3.2.0 dependabot (353)
- Bump flake8-comprehensions from 3.10.1 to 3.11.0 dependabot (352)
- Bump simplejson from 3.18.3 to 3.18.4 dependabot (351)
- Bump flake8-bugbear from 23.2.13 to 23.3.12 dependabot (350)
- Bump grpc-stubs from 1.24.12 to 1.24.12.1 dependabot (349)
- Bump codespell from 2.2.2 to 2.2.4 dependabot (347)
- Bump ipdb from 0.13.11 to 0.13.13 dependabot (348)
- Bump pylint from 2.16.4 to 2.17.0 dependabot (346)
- Bump pylint from 2.16.3 to 2.16.4 dependabot (345)
- Bump pytest from 7.2.1 to 7.2.2 dependabot (344)
- Bump faker from 17.5.0 to 17.6.0 dependabot (343)
- Bump pylint from 2.16.2 to 2.16.3 dependabot (342)
- Bump faker from 17.4.0 to 17.5.0 dependabot (341)
- Bump faker from 17.3.0 to 17.4.0 dependabot (340)
- Fix potential security vulnerabilities KapJI (339)

Resources

Use this package?

Scan your Python project for dependency vulnerabilities in two minutes

Scan your application

Severity Details

CVSS Base Score

HIGH 7.5

CVSS v3 Details

HIGH 7.5
Attack Vector (AV)
NETWORK
Attack Complexity (AC)
LOW
Privileges Required (PR)
NONE
User Interaction (UI)
NONE
Scope (S)
UNCHANGED
Confidentiality Impact (C)
NONE
Integrity Impact (I)
HIGH
Availability Availability (A)
NONE