react / react/react-native

okhttp/okio pinned at vulnerable versions (CVE-2023-3635) in gradle/libs.versions.toml, unchanged through current main

Đang mở
#58,148 2 bình luận 0 reaction 0 người được giao Xem trên GitHub

Chưa có ai nhận issue này.

Needs: Attention Needs: Repro
Ngôn ngữ chính
C++
Star
127k
Fork
25.3k
Merge trung bình
1 ngày 23 giờ
Pull request đã merge (30 ngày)
4

Mô tả

This is a dependency/security report, not a runtime crash — there's no code reproducer, since the issue is a static pinned version, not a behavior bug. Evidence is the dependency tree below instead.

Description

packages/react-native/gradle/libs.versions.toml pins:

okhttp = "4.9.2"
okio = "2.9.0"

okio 2.9.0 is affected by CVE-2023-3635 / GHSA-w33c-445m-f8w7 ("Okio Signed to Unsigned Conversion Error"), fixed in okio 3.4.0.

This isn't a transitive/incidental pull-in — it's explicitly pinned in RN's own version catalog, and it lands on the actual shipped release classpath of a consuming app (confirmed via ./gradlew :app:dependencies --configuration releaseRuntimeClasspath), not just test tooling:

com.squareup.okhttp3:okhttp:{strictly 4.9.2}
com.squareup.okio:okio:{strictly 2.9.0}

I checked whether a newer RN version already fixes this before filing — it doesn't. I compared the same file across:

  • v0.79.6 (a currently-supported release): okhttp = "4.9.2", okio = "2.9.0"
  • main (current unreleased development branch, 0.87.0-main): okhttp = "4.9.2", okio = "2.9.0" — identical, no bump even in active development

So there's no RN version, released or in development, that resolves this by upgrading.

I also tried working around it downstream, in case that's a viable interim path for consumers: resolutionStrategy.force 'com.squareup.okio:okio:3.4.0' in a consuming app's build.gradle. This fails resolution — okio 3.x split into a separate okio-jvm artifact, and something in RN's own OkHttp/Fresco dependency graph (which strictly pins okio) can't resolve against that new layout. So this isn't something a consuming app can safely patch around either; it needs to be addressed in RN's own version catalog (bumping okhttp to a release built against a patched okio, and updating the okio pin to reflect that).

Steps to reproduce

Not applicable in the usual crash-reproduction sense — this is a static dependency pin, reproducible by inspecting the file directly:

curl -s https://raw.githubusercontent.com/facebook/react-native/main/packages/react-native/gradle/libs.versions.toml | grep -E '^okhttp|^okio'

Or from any consuming app: ./gradlew :app:dependencies --configuration releaseRuntimeClasspath | grep -i okio

React Native Version

Confirmed present on 0.79.6 (currently-supported release) and on main (0.87.0-main, current development).

Affected Platforms

  • Runtime - Android
  • Build - MacOS

Output of npx @react-native-community/cli info

Not applicable — this is a static analysis of RN's own committed version catalog file, not an environment-specific issue.

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Hướng nghiên cứu

Bắt đầu với packages/react-native/gradle/libs.versions.toml và kiểm tra các phiên bản được ghim của okhttp và okio. Chạy ./gradlew :app:dependencies --configuration releaseRuntimeClasspath để xác minh các artifact release đã được phân giải và kiểm tra cấu trúc dependency trước khi thay đổi phiên bản. Hoàn tất khi catalog sử dụng các phiên bản đã được vá và tương thích, đồng thời release classpath không còn chứa phiên bản okio dễ bị tấn công.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Đánh giá

Công nghệ
android
Lĩnh vực
build-system, mobile, security
Loại issue
Lỗi
Độ khó
3/5
Thời gian dự kiến
1-2 ngày
Mức độ hoạt động
Sôi nổi
Độ rõ ràng
Đặc tả rõ ràng
Mức phù hợp với người mới
68/100

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.