Apache

Apache Calcite Avatica

2 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.64%
  • Veröffentlicht 22.09.2026 15:39:14
  • Zuletzt bearbeitet 22.09.2026 20:17:05

Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache Calcite Avatica. Plugin instantiation (via AvaticaUtils#instantiatePlugin and other methods) initializes arbitrary classes via unrestricted cal...

  • EPSS 3%
  • Veröffentlicht 28.07.2022 09:15:08
  • Zuletzt bearbeitet 21.11.2024 07:12:52

Apache Calcite Avatica JDBC driver creates HTTP client instances based on class names provided via `httpclient_impl` connection property; however, the driver does not verify if the class implements the expected interface before instantiating it, whic...