opentok-react-native-samples icon indicating copy to clipboard operation
opentok-react-native-samples copied to clipboard

okio-2.9.0.jar: 1 vulnerabilities (highest severity is: 5.9)

Open mend-for-github-com[bot] opened this issue 1 year ago • 0 comments

Vulnerable Library - okio-2.9.0.jar

A modern I/O API for Java

Library home page: https://github.com/square/okio/

Path to dependency file: /ScreenSharing/node_modules/opentok-react-native/android/build.gradle

Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/com.squareup.okio/okio/2.9.0/eaa6725bd15c851530d55f235208568dfb399bb8/okio-2.9.0.pom,/tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/com.squareup.okio/okio/2.9.0/eaa6725bd15c851530d55f235208568dfb399bb8/okio-2.9.0.pom,/tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/com.squareup.okio/okio/2.9.0/eaa6725bd15c851530d55f235208568dfb399bb8/okio-2.9.0.pom,/tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/com.squareup.okio/okio/2.9.0/eaa6725bd15c851530d55f235208568dfb399bb8/okio-2.9.0.pom,/tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/com.squareup.okio/okio/2.9.0/eaa6725bd15c851530d55f235208568dfb399bb8/okio-2.9.0.pom,/tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/com.squareup.okio/okio/2.9.0/eaa6725bd15c851530d55f235208568dfb399bb8/okio-2.9.0.pom,/tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/com.squareup.okio/okio/2.9.0/eaa6725bd15c851530d55f235208568dfb399bb8/okio-2.9.0.pom,/tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/com.squareup.okio/okio/2.9.0/eaa6725bd15c851530d55f235208568dfb399bb8/okio-2.9.0.pom,/tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/com.squareup.okio/okio/2.9.0/eaa6725bd15c851530d55f235208568dfb399bb8/okio-2.9.0.pom,/tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/com.squareup.okio/okio/2.9.0/eaa6725bd15c851530d55f235208568dfb399bb8/okio-2.9.0.pom

Found in HEAD commit: 3e09f00ece33d069067f67703d3d465195d8801f

Vulnerabilities

CVE Severity CVSS Exploit Maturity EPSS Dependency Type Fixed in (okio version) Remediation Possible** Reachability
CVE-2023-3635 Medium 5.9 Not Defined 0.1% okio-2.9.0.jar Direct 3.0.0-alpha.10

**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation

Details

CVE-2023-3635

Vulnerable Library - okio-2.9.0.jar

A modern I/O API for Java

Library home page: https://github.com/square/okio/

Path to dependency file: /ScreenSharing/node_modules/opentok-react-native/android/build.gradle

Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/com.squareup.okio/okio/2.9.0/eaa6725bd15c851530d55f235208568dfb399bb8/okio-2.9.0.pom,/tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/com.squareup.okio/okio/2.9.0/eaa6725bd15c851530d55f235208568dfb399bb8/okio-2.9.0.pom,/tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/com.squareup.okio/okio/2.9.0/eaa6725bd15c851530d55f235208568dfb399bb8/okio-2.9.0.pom,/tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/com.squareup.okio/okio/2.9.0/eaa6725bd15c851530d55f235208568dfb399bb8/okio-2.9.0.pom,/tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/com.squareup.okio/okio/2.9.0/eaa6725bd15c851530d55f235208568dfb399bb8/okio-2.9.0.pom,/tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/com.squareup.okio/okio/2.9.0/eaa6725bd15c851530d55f235208568dfb399bb8/okio-2.9.0.pom,/tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/com.squareup.okio/okio/2.9.0/eaa6725bd15c851530d55f235208568dfb399bb8/okio-2.9.0.pom,/tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/com.squareup.okio/okio/2.9.0/eaa6725bd15c851530d55f235208568dfb399bb8/okio-2.9.0.pom,/tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/com.squareup.okio/okio/2.9.0/eaa6725bd15c851530d55f235208568dfb399bb8/okio-2.9.0.pom,/tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/com.squareup.okio/okio/2.9.0/eaa6725bd15c851530d55f235208568dfb399bb8/okio-2.9.0.pom

Dependency Hierarchy:

  • :x: okio-2.9.0.jar (Vulnerable Library)

Found in HEAD commit: 3e09f00ece33d069067f67703d3d465195d8801f

Found in base branch: main

Vulnerability Details

GzipSource does not handle an exception that might be raised when parsing a malformed gzip buffer. This may lead to denial of service of the Okio client when handling a crafted GZIP archive, by using the GzipSource class.

Publish Date: 2023-07-12

URL: CVE-2023-3635

Threat Assessment

Exploit Maturity: Not Defined

EPSS: 0.1%

CVSS 3 Score Details (5.9)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: High
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: None
    • Availability Impact: High
For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: https://www.cve.org/CVERecord?id=CVE-2023-3635

Release Date: 2023-07-12

Fix Resolution: 3.0.0-alpha.10

:rescue_worker_helmet: Automatic Remediation will be attempted for this issue.


:rescue_worker_helmet:Automatic Remediation will be attempted for this issue.