« Volver al listado

CVE-2023-3635

Estado: ModificadaAlta (7.5)—

GzipSource does not handle an exception that might be raised when parsing a malformed gzip buffer. This may lead to denial of service of the Okio client when handling a crafted GZIP archive, by using the GzipSource class.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-3635",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-3635",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-10-22T17:26:23.899148Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "reefs@jfrog.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.9,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.2
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "reefs@jfrog.com",
      "affectedData": [
        {
          "versions": [
            {
              "status": "affected",
              "version": "0.5.0",
              "lessThan": "1.0.0",
              "versionType": "maven"
            },
            {
              "status": "affected",
              "version": "1.0.0",
              "lessThan": "1.17.6",
              "versionType": "maven"
            },
            {
              "status": "affected",
              "version": "2.0.0",
              "lessThan": "3.0.0",
              "versionType": "maven"
            },
            {
              "status": "affected",
              "version": "3.0.0",
              "lessThan": "3.4.0",
              "versionType": "maven"
            }
          ],
          "packageName": "com.squareup.okio:okio",
          "collectionURL": "https://mvnrepository.com",
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2023-07-12T19:15:08.983",
  "references": [
    {
      "url": "https://github.com/square/okio/commit/81bce1a30af244550b0324597720e4799281da7b",
      "tags": [
        "Patch"
      ],
      "source": "reefs@jfrog.com"
    },
    {
      "url": "https://research.jfrog.com/vulnerabilities/okio-gzip-source-unhandled-exception-dos-xray-523195/",
      "tags": [
        "Exploit",
        "Patch",
        "Third Party Advisory"
      ],
      "source": "reefs@jfrog.com"
    },
    {
      "url": "https://github.com/square/okio/commit/81bce1a30af244550b0324597720e4799281da7b",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://research.jfrog.com/vulnerabilities/okio-gzip-source-unhandled-exception-dos-xray-523195/",
      "tags": [
        "Exploit",
        "Patch",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "reefs@jfrog.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-195"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-681"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "GzipSource does not handle an exception that might be raised when parsing a malformed gzip buffer. This may lead to denial of service of the Okio client when handling a crafted GZIP archive, by using the GzipSource class.\n\n"
    },
    {
      "lang": "es",
      "value": "GzipSource no maneja una excepción que podría surgir al analizar un búfer gzip malformado. Esto puede conducir a la denegación de servicio del cliente Okio cuando se maneja un archivo GZIP manipulado, mediante el uso de la clase \"GzipSource\"."
    }
  ],
  "lastModified": "2026-06-17T06:14:30.757",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:squareup:okio:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "03403B65-FE42-46FB-B8DA-2AAFAD29C5F4",
              "versionEndExcluding": "1.17.6",
              "versionStartIncluding": "0.5.0"
            },
            {
              "criteria": "cpe:2.3:a:squareup:okio:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CC8A3FE6-BD81-4D3D-9568-E364F5D35668",
              "versionEndExcluding": "3.4.0",
              "versionStartIncluding": "2.0.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "reefs@jfrog.com"
}