GHSA-xprw-xvvm-vqmv

Suggest an improvement
Source
https://github.com/advisories/GHSA-xprw-xvvm-vqmv
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-xprw-xvvm-vqmv/GHSA-xprw-xvvm-vqmv.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-xprw-xvvm-vqmv
Aliases
  • CVE-2010-2232
Published
2022-05-17T00:29:52Z
Modified
2023-11-08T03:56:56.332350Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
Summary
Improper Access Control in Apache Derby
Details

In Apache Derby 10.1.2.1, 10.2.2.0, 10.3.1.4, and 10.4.1.3, Export processing may allow an attacker to overwrite an existing file.

Database specific
{
    "nvd_published_at": "2017-10-23T13:29:00Z",
    "github_reviewed_at": "2022-07-08T18:49:01Z",
    "severity": "HIGH",
    "github_reviewed": true,
    "cwe_ids": [
        "CWE-284"
    ]
}
References

Affected packages

Maven / org.apache.derby:derby

Package

Name
org.apache.derby:derby
View open source insights on deps.dev
Purl
pkg:maven/org.apache.derby/derby

Affected ranges

Type
ECOSYSTEM
Events
Introduced
10.1.2.1
Fixed
10.4.2.0

Affected versions

10.*

10.1.2.1
10.1.3.1
10.2.1.6
10.2.2.0
10.3.1.4
10.3.2.1
10.4.1.3

Database specific

{
    "last_known_affected_version_range": "<= 10.4.1.3"
}