5.5.2
5 years ago
1 months ago
Known vulnerabilities in the org.apache.shardingsphere:shardingsphere package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
Affected versions of this package are vulnerable to Deserialization of Untrusted Data which allows attackers to execute arbitrary code by constructing a special YAML configuration file. An attacker can use SnakeYAML to deserialize Note: The attacker needs to have permission to modify the ShardingSphere Agent YAML configuration file on the target machine, and the target machine can access the URL with the arbitrary code JAR. How to fix Deserialization of Untrusted Data? Upgrade | [,5.4.0) |