com.squareup.okhttp3:okhttp@3.0.1 vulnerabilities
-
latest version
4.12.0
-
latest non vulnerable version
-
first published
9 years ago
-
latest version published
a year ago
-
licenses detected
- [3.0.0-RC1,)
-
package manager
Direct Vulnerabilities
Known vulnerabilities in the com.squareup.okhttp3:okhttp package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.Vulnerability | Vulnerable Version |
---|---|
com.squareup.okhttp3:okhttp is a HTTP & HTTP/2 client for Android and Java applications Affected versions of this package are vulnerable to Information Exposure. When there's an illegal character in a header value, an How to fix Information Exposure? Upgrade |
[,4.9.2)
|
com.squareup.okhttp3:okhttp is HTTP & HTTP/2 client for Android and Java applications Affected versions of this package are vulnerable to SSL Certificate Bypass. It allows man-in-the-middle attackers to bypass certificate pinning by sending a certificate chain with a certificate from a non-pinned trusted CA and the pinned certificate. How to fix SSL Certificate Bypass? Upgrade |
[3.0.0,3.1.2)
|