binance / binance/binance-connector-java

Transitive dependecy of com.squareup.okhttp3:okhttp:4.9.2 is vulnerable

Open
#201 2 comments 0 reactions 0 assignees View on GitHub
Dominant language
Java
Stars
581
Forks
255
Avg merge
2m
Merged PRs (30d)
2

Description

Hi!
There is a vulnerability in latest version transitive dependency.
Details:

> Dependency maven:com.squareup.okio:okio:2.8.0 is vulnerable
>
> Update to unaffected version 3.4.0
>
> CVE-2023-3635, Score: 5.9
>
> GzipSource does not handle an exception that might be raised when parsing a malformed gzip buffer. This may lead to denial of service of the Okio client when handling a crafted GZIP archive, by using the GzipSource class.
> Mend Note: The description of this vulnerability differs from MITRE.
>
> Read More: https://www.mend.io/vulnerability-database/CVE-2023-3635
>
> Results powered by Mend.io

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.