VYPR

apk package

wolfi/trino-plugin-faker

pkg:apk/wolfi/trino-plugin-faker

Vulnerabilities (66)

  • CVE-2020-13949Feb 12, 2021
    affected < 440-r0fixed 440-r0

    In Apache Thrift 0.9.3 to 0.13.0, malicious RPC clients could send short messages which would result in a large memory allocation, potentially leading to denial of service.

  • CVE-2020-13956Dec 2, 2020
    affected < 440-r0fixed 440-r0

    Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution.

  • CVE-2019-0205Oct 28, 2019
    affected < 440-r0fixed 440-r0

    In Apache Thrift all versions up to and including 0.12.0, a server or client may run into an endless loop when feed with specific input data. Because the issue had already been partially fixed in version 0.11.0, depending on the installed version it affects only certain language

  • CVE-2019-10086Aug 20, 2019
    affected < 439-r0fixed 439-r0

    In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the Prop

  • CVE-2018-11798Jan 7, 2019
    affected < 440-r0fixed 440-r0

    The Apache Thrift Node.js static web server in versions 0.9.2 through 0.11.0 have been determined to contain a security vulnerability in which a remote user has the ability to access files outside the set webservers docroot path.

  • CVE-2012-5783Nov 4, 2012
    affected < 445-r0fixed 445-r0

    Apache Commons HttpClient 3.x, as used in Amazon Flexible Payments Service (FPS) merchant Java SDK and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows m

Page 4 of 4