Skip to content

CVE-2023-3635: related to dependency com.squareup.okio:okio-jvm:3.0.0 #1038

Description

Expected behavior

Have no security warnings in my application because microsoft-graph-core is using a vulnerable dependency. There is already a new version without the vulnerability.

Actual behavior

The dependency is vulnerable to a certain attack, according to https://nvd.nist.gov/vuln/detail/CVE-2023-3635

Steps to reproduce the behavior

N/A

Activity

  1. ramsessanchez commented on Oct 23, 2023

    @ramsessanchez
    Contributor

    Hi João Paulo Gomes (@johnowl) , thanks for this catch! Will be updating the okhttp3 dependency which takes a dependency on the okio package.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions