Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

what verison do I need to update For fixing CVE-2023-3635 #1350

Closed
ya0xu opened this issue Sep 19, 2023 · 5 comments
Closed

what verison do I need to update For fixing CVE-2023-3635 #1350

ya0xu opened this issue Sep 19, 2023 · 5 comments

Comments

@ya0xu
Copy link

ya0xu commented Sep 19, 2023

I use version com.squareup.okio:okio:1.14.0 now , what min version do I need to update For fixing CVE-2023-3635

@JakeWharton
Copy link
Collaborator

3.4.0. The link that you provided tells you affected versions and the patched version.

@JakeWharton JakeWharton closed this as not planned Won't fix, can't repro, duplicate, stale Sep 19, 2023
@swankjesse
Copy link
Collaborator

I did end up releasing 1.17.6 with this fix. But I recommend everyone upgrade to 3.6.0, it’s got other correctness & performance improvements.

@djq183u
Copy link

djq183u commented Oct 2, 2023

Hi @swankjesse, maven central still lists it as vulnerable
https://mvnrepository.com/artifact/com.squareup.okio/okio/1.17.6

And the security scanner our company uses as part of CI (Nexus Lifecycle) still flags 1.17.6. I reckon other companies scanners will find issues also.

May be a case of false positives, giving it a day or two and going to check again if those get updated and show 1.17.6 as patched, but just for your awareness.

@swankjesse
Copy link
Collaborator

I messaged the JFrog security team who reported the original CVE, and who I believe is the authority on what versions it’s fixed in. I can’t do that myself!

@djq183u
Copy link

djq183u commented Oct 3, 2023

Awesome, thank you 😃

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants