Apache Heron vulnerabilities
3 known vulnerabilities affecting apache/heron.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH1
Vulnerabilities
Page 1 of 1
CVE-2021-42010CRITICALCVSS 9.8fixed in 0.20.5-incubating2022-10-24
CVE-2021-42010 [CRITICAL] CWE-116 CVE-2021-42010: Heron versions <= 0.20.4-incubating allows CRLF log injection because of the lack of escaping in the
Heron versions <= 0.20.4-incubating allows CRLF log injection because of the lack of escaping in the log statements. Please update to version 0.20.5-incubating which addresses this issue.
nvd
CVE-2020-1964CRITICALCVSS 9.8v0.20.0-incubatingv0.20.1-incubating+1 more2020-04-16
CVE-2020-1964 [CRITICAL] CWE-502 CVE-2020-1964: It was noticed that Apache Heron 0.20.2-incubating, Release 0.20.1-incubating, and Release v-0.20.0-
It was noticed that Apache Heron 0.20.2-incubating, Release 0.20.1-incubating, and Release v-0.20.0-incubating does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerabilities (CWE-502: Deserialization of Untrusted Data).
nvd
CVE-2018-11789HIGHCVSS 7.5≥ 0.13.0, ≤ 0.17.82019-03-21
CVE-2018-11789 [HIGH] CWE-22 CVE-2018-11789: When accessing the heron-ui webpage, people can modify the file paths outside of the current contain
When accessing the heron-ui webpage, people can modify the file paths outside of the current container to access any file on the host. Example woule be modifying the parameter path= to go to the directory you would like to view. i.e. ..%2F..%2F..%2F..%2F..%2F..%2Fetc%2Fpasswd.
nvd