Severity
7.5
High severity
Details
- CVSS score
- 7.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- CWE ID
Overview
About vulnerability
GzipSource does not handle an exception that might be raised when parsing a malformed gzip buffer. This may lead to denial of service of the Okio client when handling a crafted GZIP archive, by using the GzipSource class.Details
- Affected product:
- Apache Spark , Apache Tapestry , Hibernate , Jackson , OkHttp , avro , elasticsearch , kubernetes-client , logging-log4j2 , moshi , okio , selenium , wildfly
- Affected packages:
- kubernetes-httpclient-okhttp @ 6.4.1 (+599 more)