Description of vulnerability here: square/okhttp#6738
Snyk vulnerability here: https://security.snyk.io/vuln/SNYK-JAVA-COMSQUAREUPOKHTTP3-2958044
I believe the
- com.squareup.okhttp3:logging-interceptor
- com.squareup.okhttp3:okhttp-urlconnection:3.12.12
- com.squareup.retrofit2:retrofit:2.6.4
libraries will also have to be upgraded, as they take transitive dependencies on com.squareup.okhttp3:okhttp:3.12.12