Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security Vulnerability CVE-2022-24329 for okhttp 4.9.2 #2358

Closed
Eyal-G opened this issue Sep 5, 2022 · 3 comments
Closed

Security Vulnerability CVE-2022-24329 for okhttp 4.9.2 #2358

Eyal-G opened this issue Sep 5, 2022 · 3 comments

Comments

@Eyal-G
Copy link
Contributor

Eyal-G commented Sep 5, 2022

Describe the bug
There is a security vulnerability CVE-2022-24329 for okhttp 4.9.2,
this vulnerability was fixed okhttp-#7217 from 4.10

The fix should be similar to #2099

Client Version
16.0.0

@Eyal-G Eyal-G changed the title Update okhttp To Resolve CVE-2022-24329 Security Vulnerability CVE-2022-24329 for okhttp 4.9.2 Sep 5, 2022
@brendandburns
Copy link
Contributor

Per the discussion in the vulnerability this only effects Kotlin at build time. It does not affect okhttp and it definitely doesn't affect this library, so there's not much urgency to fix this.

If you want to send a PR to update the version, we'll merge the PR and it will be included in the next release. If you want it in a specific release, you can also send cherry-pick PRs once the original PR merges.

@Eyal-G
Copy link
Contributor Author

Eyal-G commented Sep 6, 2022

Thanks @brendandburns for the response.
I agree that the vulnerability does not affect the library,
I will create PR that will bump the okhttp to 4.10.0 for the next release.

@Eyal-G
Copy link
Contributor Author

Eyal-G commented Sep 8, 2022

Closing the issue after merging the code.

@Eyal-G Eyal-G closed this as completed Sep 8, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants