Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-3782


DoS of the OkHttp client when using a BrotliInterceptor and surfing to a malicious web server, or when an attacker can perform MitM to inject a Brotli zip-bomb into an HTTP response


Published

2023-07-19T21:15:10.093

Last Modified

2024-11-21T08:18:02.990

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.9 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-400
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application squareup okhttp-brotli * Yes

References