Skip to content

Transitive dependecy of com.squareup.okhttp3:okhttp:4.9.2 is vulnerable #201

@bex1111

Description

@bex1111

Hi!
There is a vulnerability in latest version transitive dependency.
Details:

Dependency maven:com.squareup.okio:okio:2.8.0 is vulnerable

Update to unaffected version 3.4.0

CVE-2023-3635, Score: 5.9

GzipSource does not handle an exception that might be raised when parsing a malformed gzip buffer. This may lead to denial of service of the Okio client when handling a crafted GZIP archive, by using the GzipSource class.
Mend Note: The description of this vulnerability differs from MITRE.

Read More: https://www.mend.io/vulnerability-database/CVE-2023-3635

Results powered by Mend.io

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions