- 
                Notifications
    
You must be signed in to change notification settings  - Fork 0
 
Description
 Vulnerable Library - okhttp-3.12.12.jar
An HTTP+HTTP/2 client for Android and Java applications
Library home page: https://github.com/square/okhttp
Path to dependency file: /hadoop-cloud/pom.xml
Path to vulnerable library: /hadoop-cloud/pom.xml
Found in HEAD commit: eb4a123ac71f425039cbf2b066115e480b3e6cc6
Vulnerabilities
| Vulnerability | Severity | Dependency | Type | Fixed in (okhttp version) | Remediation Possible** | |
|---|---|---|---|---|---|---|
| CVE-2023-0833 | 4.7 | okhttp-3.12.12.jar | Direct | 4.9.2 | ✅ | 
**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation
Details
 CVE-2023-0833
Vulnerable Library - okhttp-3.12.12.jar
An HTTP+HTTP/2 client for Android and Java applications
Library home page: https://github.com/square/okhttp
Path to dependency file: /hadoop-cloud/pom.xml
Path to vulnerable library: /hadoop-cloud/pom.xml
Dependency Hierarchy:
- ❌ okhttp-3.12.12.jar (Vulnerable Library)
 
Found in HEAD commit: eb4a123ac71f425039cbf2b066115e480b3e6cc6
Found in base branch: master
Vulnerability Details
A flaw was found in Red Hat's AMQ-Streams, which ships a version of the OKHttp component with an information disclosure flaw via an exception triggered by a header containing an illegal value. This issue could allow an authenticated attacker to access information outside of their regular permissions.
Publish Date: 2023-09-27
URL: CVE-2023-0833
CVSS 3 Score Details (4.7)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Local
 - Attack Complexity: High
 - Privileges Required: Low
 - User Interaction: None
 - Scope: Unchanged
 
 - Impact Metrics:
- Confidentiality Impact: High
 - Integrity Impact: None
 - Availability Impact: None
 
 
Suggested Fix
Type: Upgrade version
Origin: square/okhttp#6738
Release Date: 2023-09-27
Fix Resolution: 4.9.2
⛑️ Automatic Remediation will be attempted for this issue.
⛑️Automatic Remediation will be attempted for this issue.