Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-3635

Опубликовано: 12 июл. 2023
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

GzipSource does not handle an exception that might be raised when parsing a malformed gzip buffer. This may lead to denial of service of the Okio client when handling a crafted GZIP archive, by using the GzipSource class.

A flaw was found in SquareUp Okio. A class GzipSource does not handle an exception that might be raised when parsing a malformed gzip buffer. This issue may allow a malicious user to start processing a malformed file, which can result in a Denial of Service (DoS).

Отчет

Red Hat JBoss Enterprise Application Platform XP does contain Okio package but is not using GzipSource.java, which is the affected class. Red Hat support for Spring Boot is considered low impact as it's used by Dekorate during compilation process and not included in the resulting Jar.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Cryostat 2okioNot affected
Red Hat build of Apicurio Registry 2okioAffected
Red Hat CodeReady Studio 12okioOut of support scope
Red Hat Data Grid 8okioFix deferred
Red Hat Decision Manager 7okioOut of support scope
Red Hat JBoss Enterprise Application Platform 7okioNot affected
Red Hat JBoss Fuse 6okioOut of support scope
Red Hat OpenShift Application RuntimesokioWill not fix
Red Hat OpenShift Container Platform 3.11openshift3/metrics-hawkular-metricsOut of support scope
Red Hat OpenShift Container Platform 3.11openshift3/ose-logging-elasticsearch5Out of support scope

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-248
https://bugzilla.redhat.com/show_bug.cgi?id=2229295okio: GzipSource class improper exception handling

EPSS

Процентиль: 61%
0.00417
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 5.9
ubuntu
больше 2 лет назад

GzipSource does not handle an exception that might be raised when parsing a malformed gzip buffer. This may lead to denial of service of the Okio client when handling a crafted GZIP archive, by using the GzipSource class.

CVSS3: 5.9
nvd
больше 2 лет назад

GzipSource does not handle an exception that might be raised when parsing a malformed gzip buffer. This may lead to denial of service of the Okio client when handling a crafted GZIP archive, by using the GzipSource class.

CVSS3: 5.9
debian
больше 2 лет назад

GzipSource does not handle an exception that might be raised when pars ...

CVSS3: 5.9
github
больше 2 лет назад

Okio Signed to Unsigned Conversion Error vulnerability

CVSS3: 7.5
fstec
больше 2 лет назад

Уязвимость компонента GzipSource клиентской HTTP-библиотеки Okio, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 61%
0.00417
Низкий

7.5 High

CVSS3