Skip to content

CVE-2023-3635: related to dependency com.squareup.okio:okio-jvm:3.0.0 #1038

@johnowl

Description

@johnowl

Expected behavior

Have no security warnings in my application because microsoft-graph-core is using a vulnerable dependency. There is already a new version without the vulnerability.

Actual behavior

The dependency is vulnerable to a certain attack, according to https://nvd.nist.gov/vuln/detail/CVE-2023-3635

Steps to reproduce the behavior

N/A

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions