org.apache.beam:beam-sdks-java-io-mongodb@2.15.0 vulnerabilities

  • latest version

    2.65.0

  • latest non vulnerable version

  • first published

    8 years ago

  • latest version published

    1 months ago

  • licenses detected

  • package registry

  • Direct Vulnerabilities

    Known vulnerabilities in the org.apache.beam:beam-sdks-java-io-mongodb package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • H
    Insecure Defaults

    org.apache.beam:beam-sdks-java-io-mongodb is an unified programming model for Batch and Streaming.

    Affected versions of this package are vulnerable to Insecure Defaults. It has an option to disable SSL trust verification. However this configuration is not respected and the certificate verification disables trust verification in every case. This exclusion also gets registered globally which disables trust checking for any code running in the same JVM.

    How to fix Insecure Defaults?

    Upgrade org.apache.beam:beam-sdks-java-io-mongodb to version 2.17.0 or higher.

    [2.10.0,2.17.0)