It was noticed that Apache Heron 0.20.2-incubating, Release 0.20.1-incubating, and Release v-0.20.0-incubating does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerabilities (CWE-502: Deserialization of Untrusted Data).
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Heron | Apache | 0.20.0-incubating (including) | 0.20.0-incubating (including) |
Heron | Apache | 0.20.1-incubating (including) | 0.20.1-incubating (including) |
Heron | Apache | 0.20.2-incubating (including) | 0.20.2-incubating (including) |