2.0.2-1
2 years ago
13 days ago
Known vulnerabilities in the org.apache.iotdb:node-commons package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
Affected versions of this package are vulnerable to Insertion of Sensitive Information into Log File via the How to fix Insertion of Sensitive Information into Log File? Upgrade | [0.10.0,1.3.4)[2.0.1-beta,2.0.2) |
Affected versions of this package are vulnerable to Arbitrary Code Injection through the registration of user-defined functions (UDFs) from untrusted sources. An attacker with the privilege to create UDFs can execute arbitrary code by registering a malicious function. How to fix Arbitrary Code Injection? Upgrade | [1.0.0,1.3.4) |