CVE-2023-3635

ADVISORY - github

Summary

GzipSource does not handle an exception that might be raised when parsing a malformed gzip buffer. This may lead to denial of service of the Okio client when handling a crafted GZIP archive, by using the GzipSource class.

EPSS Score: 0.00498 (0.659)

Common Weakness Enumeration (CWE)

ADVISORY - nist

Signed to Unsigned Conversion Error

Incorrect Conversion between Numeric Types

ADVISORY - github

Signed to Unsigned Conversion Error

Incorrect Conversion between Numeric Types

ADVISORY - gitlab

OWASP Top Ten 2017 Category A9 - Using Components with Known Vulnerabilities

Incorrect Conversion between Numeric Types

OWASP Top Ten 2013 Category A9 - Using Components with Known Vulnerabilities

ADVISORY - redhat

Uncaught Exception


Sign in to Docker Scout

See which of your images are affected by this CVE and how to fix them by signing into Docker Scout.

Sign in