Skip to content

clickhouse-jdbc-0.6.0-patch3-all.jar includes CVE-2023-3635 #1585

@jjtt

Description

@jjtt

The included com.squareup.okio:okio should be updated to version 1.17.6 from the current 1.17.5

I have no idea if the vulnerability itself has any effect in this JDBC driver use case, but updating the dependency seems like the easiest solution.

Metadata

Metadata

Assignees

Labels

area:dependenciesPull requests that update a dependency file

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions