GzipSource does not handle an exception that might be raised when parsing a malformed gzip buffer. This may lead to denial of service of the Okio client when handling a crafted GZIP archive, by using the GzipSource class.

Project Subscriptions

Vendors Products
Amq Streams Subscribe
Jboss Enterprise Bpms Platform Subscribe
Jboss Fuse Subscribe
Jbosseapxp Subscribe
Openshift Devspaces Subscribe
Squareup Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2023-2158 GzipSource does not handle an exception that might be raised when parsing a malformed gzip buffer. This may lead to denial of service of the Okio client when handling a crafted GZIP archive, by using the GzipSource class.
Github GHSA Github GHSA GHSA-w33c-445m-f8w7 Okio Signed to Unsigned Conversion Error vulnerability
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 16 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00247}

epss

{'score': 0.00222}


Wed, 30 Oct 2024 02:15:00 +0000

Type Values Removed Values Added
First Time appeared Redhat openshift Devspaces
CPEs cpe:/a:redhat:openshift_devspaces:3::el8
Vendors & Products Redhat openshift Devspaces

Wed, 23 Oct 2024 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: JFROG

Published:

Updated: 2024-10-23T13:32:52.994Z

Reserved: 2023-07-12T12:46:57.470Z

Link: CVE-2023-3635

cve-icon Vulnrichment

Updated: 2024-08-02T07:01:57.503Z

cve-icon NVD

Status : Modified

Published: 2023-07-12T19:15:08.983

Modified: 2024-11-21T08:17:43.213

Link: CVE-2023-3635

cve-icon Redhat

Severity : Important

Publid Date: 2023-07-12T00:00:00Z

Links: CVE-2023-3635 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses