Uploaded image for project: 'Derby'
  1. Derby
  2. DERBY-7135

Does derby 10.14.2.0 contain the CVE-2020-13949 vulnerability?

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Closed
    • Blocker
    • Resolution: Not A Problem
    • 10.14.2.0
    • None
    • None
    • None
    • Blocker

    Description

      Use a security tool to scan the derby 10.14.2.0 installation package. The result shows that derbynet.jar contains the CVE-2020-13949 vulnerability. The vulnerability is related to  Hive and Thrift, but no reference is found in the derby 10.14.2.0 source code.

      Is it a false positive? Which of the following application scenarios will be affected if the vulnerability is involved?

      For details about the scanning result, see the attachment.

      Vulnerability Details:

      https://nvd.nist.gov/vuln/detail/CVE-2020-13949

      Attachments

        1. Snipaste_2022-03-22_00-43-37.png
          52 kB
          JenickLee
        2. Snipaste_2022-03-22_00-51-12.png
          82 kB
          JenickLee

        Activity

          People

            Unassigned Unassigned
            难得糊涂 JenickLee
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: