Vulnerabilities (CVE)

Filtered by vendor Apache Subscribe
Filtered by product Heron
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-42010 1 Apache 1 Heron 2023-08-08 N/A 9.8 CRITICAL
Heron versions <= 0.20.4-incubating allows CRLF log injection because of the lack of escaping in the log statements. Please update to version 0.20.5-incubating which addresses this issue.
CVE-2020-1964 1 Apache 1 Heron 2020-06-15 7.5 HIGH 9.8 CRITICAL
It was noticed that Apache Heron 0.20.2-incubating, Release 0.20.1-incubating, and Release v-0.20.0-incubating does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerabilities (CWE-502: Deserialization of Untrusted Data).