socketio/socket.io-client-java

OkHttp vulnerability issues in Socket.io client dependency

shivamsharma2710 opened this issue · 1 comments

Socket.IO Library has two vulnerabilities which are coming out from the internal OkHttp dependency. I've used the latest socket.io v2.1.0 which is using very old version 3.12.12 of OkHttp.

Following are the vulnerabilities:

  1. Improper Certificate Validation

  2. Information Exposure

Please give an estimate on when you're planning to fix these vulnerabilities?

PFA the complete vulnerability report,

Screenshot 2022-10-12 at 4 21 38 AM

@darrachequesne Please give an ETA when will be new release coming out with this fix?