1.41.0
11 years ago
7 months ago
Known vulnerabilities in the org.apache.calcite:calcite-core package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
org.apache.calcite:calcite-core is a Core Calcite APIs and engine. Affected versions of this package are vulnerable to Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') via user-controled models. An attacker can achieve arbitrary code execution by supplying a crafted input that causes the system to load attacker-controlled classes. How to fix Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')? Upgrade | [,1.42.0) |
org.apache.calcite:calcite-core is a Core Calcite APIs and engine. Affected versions of this package are vulnerable to Man-in-the-Middle (MitM). The The method itself is in a utility class so people may use it to create vulnerable HTTPS connections for other applications. How to fix Man-in-the-Middle (MitM)? Upgrade | [,1.26) |