Arrow Apache Arrow

Do you want an email whenever new security vulnerabilities are reported in Apache Arrow?

By the Year

In 2024 there have been 0 vulnerabilities in Apache Arrow . Arrow did not have any published security vulnerabilities last year.

Year Vulnerabilities Average Score
2024 0 0.00
2023 0 0.00
2022 0 0.00
2021 0 0.00
2020 0 0.00
2019 2 7.50
2018 0 0.00

It may take a day or so for new Arrow vulnerabilities to show up in the stats or in the list of recent security vulnerabilties. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Apache Arrow Security Vulnerabilities

It was discovered that the C++ implementation (

CVE-2019-12408 7.5 - High - November 08, 2019

It was discovered that the C++ implementation (which underlies the R, Python and Ruby implementations) of Apache Arrow 0.14.0 to 0.14.1 had a uninitialized memory bug when building arrays with null values in some cases. This can lead to uninitialized memory being unintentionally shared if Arrow Arrays are transmitted over the wire (for instance with Flight) or persisted in the streaming IPC and file formats.

Missing Initialization of Resource

While investigating UBSAN errors in https://github.com/apache/arrow/pull/5365 it was discovered Apache Arrow versions 0.12.0 to 0.14.1, left memory Array data uninitialized when reading RLE null data

CVE-2019-12410 7.5 - High - November 08, 2019

While investigating UBSAN errors in https://github.com/apache/arrow/pull/5365 it was discovered Apache Arrow versions 0.12.0 to 0.14.1, left memory Array data uninitialized when reading RLE null data from parquet. This affected the C++, Python, Ruby and R implementations. The uninitialized memory could potentially be shared if are transmitted over the wire (for instance with Flight) or persisted in the streaming IPC and file formats.

Missing Initialization of Resource

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Apache Arrow or by Apache? Click the Watch button to subscribe.

Apache
Vendor

Apache Arrow
Product

subscribe