3.0.0-M3
2 months ago
19 days ago
Known vulnerabilities in the org.apache.opennlp:opennlp-api package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
Affected versions of this package are vulnerable to Unsafe Reflection that leads to arbitrary class instantiation, via the This is only exploitable if a class with attacker-controlled side effects in its static initializer or no-argument constructor is present on the classpath, and the attacker is able to supply a model archive from an untrusted source, such as a shared Hugging Face model. Note: The fix for this vulnerability involves an allowlist approach, a consequence of which is that classes under the How to fix Unsafe Reflection? Upgrade | [3.0.0-M1,3.0.0-M3) |