Tinkerpop Apache Tinkerpop

Do you want an email whenever new security vulnerabilities are reported in Apache Tinkerpop?

By the Year

In 2022 there have been 0 vulnerabilities in Apache Tinkerpop . Last year Tinkerpop had 2 security vulnerabilities published. Right now, Tinkerpop is on track to have less security vulnerabilities in 2022 than it did last year.

Year Vulnerabilities Average Score
2022 0 0.00
2021 2 7.50
2020 0 0.00
2019 0 0.00
2018 0 0.00

It may take a day or so for new Tinkerpop vulnerabilities to show up in the stats or in the list of recent security vulnerabilties. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Apache Tinkerpop Security Vulnerabilities

The Snappy frame decoder function doesn't restrict the chunk length which may lead to excessive memory usage

CVE-2021-37137 7.5 - High - October 19, 2021

The Snappy frame decoder function doesn't restrict the chunk length which may lead to excessive memory usage. Beside this it also may buffer reserved skippable chunks until the whole chunk was received which may lead to excessive memory usage as well. This vulnerability can be triggered by supplying malicious input that decompresses to a very big size (via a network stream or a file) or by sending a huge skippable chunk.

Resource Exhaustion

The Bzip2 decompression decoder function doesn't

CVE-2021-37136 7.5 - High - October 19, 2021

The Bzip2 decompression decoder function doesn't allow setting size restrictions on the decompressed output data (which affects the allocation size used during decompression). All users of Bzip2Decoder are affected. The malicious input can trigger an OOME and so a DoS attack

Resource Exhaustion

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for NetApp Oncommand Insight or by Apache? Click the Watch button to subscribe.

Apache
Vendor

subscribe