You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Affected versions of this package are vulnerable to Information Exposure. When there's an illegal character in a header value, an IllegalArgumentException is thrown whose message includes the full header value.
CVE-2023-0833 - Information Exposure in com.squareup.okhttp3:okhttp
com.squareup.okhttp3:okhttp
Introduced through: org.keycloak:[email protected] › io.fabric8:[email protected] › io.fabric8:[email protected] › io.fabric8:[email protected] › com.squareup.okhttp3:[email protected]
Overview
com.squareup.okhttp3:okhttp is a HTTP & HTTP/2 client for Android and Java applications
Affected versions of this package are vulnerable to Information Exposure. When there's an illegal character in a header value, an
IllegalArgumentException
is thrown whose message includes the full header value.PoC
Remediation
Upgrade
com.squareup.okhttp3:okhttp
to version 4.9.2 or higher.References
The text was updated successfully, but these errors were encountered: