1.4.1
10 months ago
15 days ago
Known vulnerabilities in the org.apache.polaris:polaris-runtime-service package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
org.apache.polaris:polaris-runtime-service is an a catalog for data lakes. It provides new levels of choice, flexibility and control over data, with full enterprise security and Apache Iceberg interoperability across a multitude of engines and infrastructure Affected versions of this package are vulnerable to Missing Authorization via staged table creation. An attacker can obtain broad temporary storage credentials for an arbitrary location by supplying a custom How to fix Missing Authorization? Upgrade | [,1.4.1) |
org.apache.polaris:polaris-runtime-service is an a catalog for data lakes. It provides new levels of choice, flexibility and control over data, with full enterprise security and Apache Iceberg interoperability across a multitude of engines and infrastructure Affected versions of this package are vulnerable to Incorrect Authorization through the optional Note: This is only exploitable if How to fix Incorrect Authorization? Upgrade | [,1.4.1) |