CVE-2023-3635: related to dependency com.squareup.okio:okio-jvm:3.0.0 #1038
Copy link
Copy link
Closed
Labels
Description
Activity
- addedquestionFurther information is requestedFurther information is requested
on Aug 8, 2023 ramsessanchez commented
on Oct 23, 2023 ContributorMore actionsHi João Paulo Gomes (@johnowl) , thanks for this catch! Will be updating the okhttp3 dependency which takes a dependency on the okio package.
Reacted by João Paulo Gomes- linked a pull request that will close this issueUpdate Dependencies #1251
on Oct 24, 2023
Expected behavior
Have no security warnings in my application because microsoft-graph-core is using a vulnerable dependency. There is already a new version without the vulnerability.
Actual behavior
The dependency is vulnerable to a certain attack, according to https://nvd.nist.gov/vuln/detail/CVE-2023-3635
Steps to reproduce the behavior
N/A