CVE-2023-3635
Okio Signed to Unsigned Conversion Error vulnerability
5.9
MEDIUM
CVSS 3.1
EPSS 0.57%
Description
GzipSource does not handle an exception that might be raised when parsing a malformed gzip buffer. This may lead to denial of service of the Okio client when handling a crafted GZIP archive, by using the GzipSource class.
How to fix CVE-2023-3635
To remediate CVE-2023-3635, upgrade the affected package to a fixed version below.
- Maven/com.squareup.okio:okio—upgrade to 3.4.0 or later
- —upgrade to 3.4.0 or later
Is CVE-2023-3635 being exploited?
Low — EPSS is 0.6%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- >= 2.0.0-RC1, < 3.4.0
- >= 2.0.0-RC1, < 3.4.0
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.9 | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H |