GHSA-v7cq-pq7v-mh5v

Suggest an improvement
Source
https://github.com/advisories/GHSA-v7cq-pq7v-mh5v
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-v7cq-pq7v-mh5v/GHSA-v7cq-pq7v-mh5v.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-v7cq-pq7v-mh5v
Aliases
  • CVE-2006-7217
Published
2022-05-01T07:45:41Z
Modified
2024-11-28T05:34:46.520969Z
Summary
Apache Derby SQL Injection
Details

Apache Derby before 10.2.1.6 does not determine schema privilege requirements during the DropSchemaNode bind phase, which allows remote authenticated users to execute arbitrary drop schema statements in SQL authorization mode.

Database specific
{
    "nvd_published_at": "2007-07-05T20:30:00Z",
    "cwe_ids": [
        "CWE-89"
    ],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2024-02-12T16:48:29Z"
}
References

Affected packages

Maven / org.apache.derby:derby

Package

Name
org.apache.derby:derby
View open source insights on deps.dev
Purl
pkg:maven/org.apache.derby/derby

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
10.2.1.6

Affected versions

10.*

10.1.1.0
10.1.2.1
10.1.3.1