Skip to content

Mockwebserver has transitive vulnerability dependency on okio:3.2.0 and results in CVE-2023-3635 #7986

@sshankarbayari

Description

@sshankarbayari

Hi,

We are using the dependency on com.squareup.okhttp3:mockwebserver and this has a transitive dependency on com.squareup.okio:okio:3.2.0.
+--- com.squareup.okhttp3:mockwebserver:5.0.0-alpha.11
| +--- com.squareup.okhttp3:okhttp:5.0.0-alpha.11
| | --- com.squareup.okhttp3:okhttp-jvm:5.0.0-alpha.11
| | +--- com.squareup.okio:okio:3.2.0
| | | --- com.squareup.okio:okio-jvm:3.2.0

okio-3.2.0 has a vulnerability that has been identified in one of our Fossa scans. The vul CVE-2023-3635 has been resolved in version 3.4.0 and above. The dependency version has to be updated to >3.4.0
CVE-2023-3635

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugBug in existing code

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions