GHSA-hjgm-f7vx-m5g7
HIGHCVE-2020-1964It was noticed that Apache Heron 0.20.2-incubating, Release 0.20.1-incubating, and Release v-0.20.0-incubating does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerabilities (CWE-502: Deserialization of Untrusted Data).
- Affected
- >= 0.20.0-incubating, <= 0.20.2-incubating
- Fixed in
- 0.20.3-incubating
- Weakness
- CWE-502
- Published
- 2022-01-06
- Source
- github