CVE-2023-3635
Okio Signed to Unsigned Conversion Error vulnerability
Description
GzipSource does not handle an exception that might be raised when parsing a malformed gzip buffer. This may lead to denial of service of the Okio client when handling a crafted GZIP archive, by using the GzipSource class.
Base CVSS
7.5
EPSS Score
0.25%
Introduced Version
0.5.0
Fix Available
1.17.6,3.4.0
Available Patches
Package
CVEs Fixed
Lines of Code Changed