Описание
DoS of the OkHttp client when using a BrotliInterceptor and surfing to a malicious web server, or when an attacker can perform MitM to inject a Brotli zip-bomb into an HTTP response
Ссылки
- Issue TrackingVendor Advisory
- ExploitThird Party Advisory
- Issue TrackingVendor Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:squareup:okhttp-brotli:*:*:*:*:*:*:*:*
EPSS
Процентиль: 42%
0.00203
Низкий
5.9 Medium
CVSS3
Дефекты
CWE-400
NVD-CWE-noinfo
Связанные уязвимости
CVSS3: 5.9
github
больше 2 лет назад
DoS of the OkHttp client when using a BrotliInterceptor and surfing to a malicious web server, or when an attacker can perform MitM to inject a Brotli zip-bomb into an HTTP response
EPSS
Процентиль: 42%
0.00203
Низкий
5.9 Medium
CVSS3
Дефекты
CWE-400
NVD-CWE-noinfo