Skip to content

okhttp update to 4.9.2 #29726

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed
meier-th opened this issue Feb 10, 2022 · 1 comment
Closed

okhttp update to 4.9.2 #29726

meier-th opened this issue Feb 10, 2022 · 1 comment
Labels
status: invalid An issue that we don't feel is valid

Comments

@meier-th
Copy link

okhttp library is vulnerable to an information disclosure issue due to how the contents of sensitive headers, such as the Authorization header, can be logged when an IllegalArgumentException is thrown.

This issue could allow an attacker or malicious user who has access to the logs to obtain the sensitive contents of the affected headers which could facilitate further attacks.

Fixed in 5.0.0-alpha3 by this commit. The fix was cherry-picked and backported into 4.9.2 with this commit.

Requesting you to clarify if this dependency will be updated to a fixed version in the following releases

@spring-projects-issues spring-projects-issues added the status: waiting-for-triage An issue we've not yet triaged label Feb 10, 2022
@snicoll
Copy link
Member

snicoll commented Feb 10, 2022

@meier-th please search the issue tracker before raising issues like this. There is already a conversation about oktthp 4.

@snicoll snicoll closed this as completed Feb 10, 2022
@snicoll snicoll added status: invalid An issue that we don't feel is valid and removed status: waiting-for-triage An issue we've not yet triaged labels Feb 10, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
status: invalid An issue that we don't feel is valid
Projects
None yet
Development

No branches or pull requests

3 participants