Uploaded image for project: 'Hadoop Common'
  1. Hadoop Common
  2. HADOOP-18837

Upgrade Okio to 3.4.0 due to CVE-2023-3635

    XMLWordPrintableJSON

Details

    • Reviewed

    Description

      Upgrade Okio to 3.4.0 due to CVE-2023-3635

      GzipSource does not handle an exception that might be raised when parsing a malformed gzip buffer. This may lead to denial of service of the Okio client when handling a crafted GZIP archive, by using the GzipSource class.

      CVSSv3 Score:- 7.5(High)

      https://nvd.nist.gov/vuln/detail/CVE-2023-3635 

      Attachments

        Issue Links

          Activity

            People

              rohit.kumar Rohit Kumar
              rohit.kumar Rohit Kumar
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: