VYPR

Maven package

org.apache.calcite/calcite-splunk

pkg:maven/org.apache.calcite/calcite-splunk

Vulnerabilities (1)

  • CVE-2020-13955Oct 9, 2020
    affected < 1.26.0fixed 1.26.0

    HttpUtils#getURLConnection method disables explicitly hostname verification for HTTPS connections making clients vulnerable to man-in-the-middle attacks. Calcite uses internally this method to connect with Druid and Splunk so information leakage may happen when using the respecti