CVE Vulnerabilities

CVE-2023-3635

Incorrect Conversion between Numeric Types

Published: Jul 12, 2023 | Modified: Oct 25, 2023
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
7.5 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM

GzipSource does not handle an exception that might be raised when parsing a malformed gzip buffer. This may lead to denial of service of the Okio client when handling a crafted GZIP archive, by using the GzipSource class.

Weakness

When converting from one data type to another, such as long to integer, data can be omitted or translated in a way that produces unexpected values. If the resulting values are used in a sensitive context, then dangerous behaviors may occur.

Affected Software

Name Vendor Start Version End Version
Okio Squareup 0.5.0 (including) 1.17.6 (excluding)
Okio Squareup 2.0.0 (including) 3.4.0 (excluding)
Red Hat AMQ Streams 2.5.0 RedHat *
Red Hat Fuse 7.12.1 RedHat okio *
Red Hat JBoss Enterprise Application Platform Expansion Pack RedHat okio *
Red Hat OpenShift Dev Spaces 3 Containers RedHat devspaces/code-rhel8:3.16-20 *
Red Hat OpenShift Dev Spaces 3 Containers RedHat devspaces/configbump-rhel8:3.16-4 *
Red Hat OpenShift Dev Spaces 3 Containers RedHat devspaces/dashboard-rhel8:3.16-27 *
Red Hat OpenShift Dev Spaces 3 Containers RedHat devspaces/devfileregistry-rhel8:3.16-67 *
Red Hat OpenShift Dev Spaces 3 Containers RedHat devspaces/devspaces-operator-bundle:3.16-70 *
Red Hat OpenShift Dev Spaces 3 Containers RedHat devspaces/devspaces-rhel8-operator:3.16-11 *
Red Hat OpenShift Dev Spaces 3 Containers RedHat devspaces/idea-rhel8:3.16-3 *
Red Hat OpenShift Dev Spaces 3 Containers RedHat devspaces/imagepuller-rhel8:3.16-3 *
Red Hat OpenShift Dev Spaces 3 Containers RedHat devspaces/machineexec-rhel8:3.16-6 *
Red Hat OpenShift Dev Spaces 3 Containers RedHat devspaces/pluginregistry-rhel8:3.16-16 *
Red Hat OpenShift Dev Spaces 3 Containers RedHat devspaces/server-rhel8:3.16-14 *
Red Hat OpenShift Dev Spaces 3 Containers RedHat devspaces/traefik-rhel8:3.16-2 *
Red Hat OpenShift Dev Spaces 3 Containers RedHat devspaces/udi-rhel8:3.16-6 *
RHPAM 7.13.5 async RedHat okio *
Okio Ubuntu bionic *
Okio Ubuntu kinetic *
Okio Ubuntu lunar *
Okio Ubuntu mantic *
Okio Ubuntu trusty *
Okio Ubuntu xenial *

Potential Mitigations

References