Packages you depend on that have known security holes (CVEs).
-
Serious CVE-2015-7501 apache-commons-collections: InvokerTransformer code execution during deserialisation
tensorflow/java/maven/pom.xml
A package you depend on has a known security hole (CVE-2015-7501). Fix: Update that package to its patched version.
-
Serious CVE-2019-20444 netty: HTTP request smuggling
tensorflow/java/maven/pom.xml
A package you depend on has a known security hole (CVE-2019-20444). Fix: Update that package to its patched version.
-
Serious CVE-2024-47561 apache-avro: Schema parsing may trigger Remote Code Execution (RCE)
tensorflow/java/maven/pom.xml
A package you depend on has a known security hole (CVE-2024-47561). Fix: Update that package to its patched version.
-
Serious CVE-2021-37404 hadoop-hdfs: Heap buffer overflow in Apache Hadoop libhdfs
tensorflow/java/maven/pom.xml
A package you depend on has a known security hole (CVE-2021-37404). Fix: Update that package to its patched version.
-
Serious CVE-2022-25168 hadoop: Command injection in org.apache.hadoop.fs.FileUtil.unTarUsingTar
tensorflow/java/maven/pom.xml
A package you depend on has a known security hole (CVE-2022-25168). Fix: Update that package to its patched version.
-
Serious CVE-2022-26612 hadoop: Arbitrary file write in FileUtil#unpackEntries on Windows
tensorflow/java/maven/pom.xml
A package you depend on has a known security hole (CVE-2022-26612). Fix: Update that package to its patched version.
-
Serious CVE-2023-44981 zookeeper: Authorization Bypass in Apache ZooKeeper
tensorflow/java/maven/pom.xml
A package you depend on has a known security hole (CVE-2023-44981). Fix: Update that package to its patched version.
-
Serious CVE-2015-7501 apache-commons-collections: InvokerTransformer code execution during deserialisation
tensorflow/java/maven/tensorflow-hadoop/pom.xml
A package you depend on has a known security hole (CVE-2015-7501). Fix: Update that package to its patched version.
-
Serious CVE-2019-20444 netty: HTTP request smuggling
tensorflow/java/maven/tensorflow-hadoop/pom.xml
A package you depend on has a known security hole (CVE-2019-20444). Fix: Update that package to its patched version.
-
Serious CVE-2024-47561 apache-avro: Schema parsing may trigger Remote Code Execution (RCE)
tensorflow/java/maven/tensorflow-hadoop/pom.xml
A package you depend on has a known security hole (CVE-2024-47561). Fix: Update that package to its patched version.
-
Serious CVE-2021-37404 hadoop-hdfs: Heap buffer overflow in Apache Hadoop libhdfs
tensorflow/java/maven/tensorflow-hadoop/pom.xml
A package you depend on has a known security hole (CVE-2021-37404). Fix: Update that package to its patched version.
-
Serious CVE-2022-25168 hadoop: Command injection in org.apache.hadoop.fs.FileUtil.unTarUsingTar
tensorflow/java/maven/tensorflow-hadoop/pom.xml
A package you depend on has a known security hole (CVE-2022-25168). Fix: Update that package to its patched version.
-
Serious CVE-2022-26612 hadoop: Arbitrary file write in FileUtil#unpackEntries on Windows
tensorflow/java/maven/tensorflow-hadoop/pom.xml
A package you depend on has a known security hole (CVE-2022-26612). Fix: Update that package to its patched version.
-
Serious CVE-2023-44981 zookeeper: Authorization Bypass in Apache ZooKeeper
tensorflow/java/maven/tensorflow-hadoop/pom.xml
A package you depend on has a known security hole (CVE-2023-44981). Fix: Update that package to its patched version.
-
Worth fixing CVE-2022-25647 com.google.code.gson-gson: Deserialization of Untrusted Data in com.google.code.gson-gson
tensorflow/java/maven/pom.xml
A package you depend on has a known security hole (CVE-2022-25647). Fix: Update that package to its patched version.
-
Worth fixing CVE-2018-10237 guava: Unbounded memory allocation in AtomicDoubleArray and CompoundOrdering classes allow remote attackers to cause a denial of service
tensorflow/java/maven/pom.xml
A package you depend on has a known security hole (CVE-2018-10237). Fix: Update that package to its patched version.
-
Worth fixing CVE-2023-2976 guava: insecure temporary directory creation
tensorflow/java/maven/pom.xml
A package you depend on has a known security hole (CVE-2023-2976). Fix: Update that package to its patched version.
-
Worth fixing CVE-2021-22569 protobuf-java: potential DoS in the parsing procedure for binary data
tensorflow/java/maven/pom.xml
A package you depend on has a known security hole (CVE-2021-22569). Fix: Update that package to its patched version.
-
Worth fixing CVE-2022-3509 protobuf-java: Textformat parsing issue leads to DoS
tensorflow/java/maven/pom.xml
A package you depend on has a known security hole (CVE-2022-3509). Fix: Update that package to its patched version.
-
Worth fixing CVE-2022-3510 protobuf-java: Message-Type Extensions parsing issue leads to DoS
tensorflow/java/maven/pom.xml
A package you depend on has a known security hole (CVE-2022-3510). Fix: Update that package to its patched version.
-
Worth fixing CVE-2024-7254 protobuf: StackOverflow vulnerability in Protocol Buffers
tensorflow/java/maven/pom.xml
A package you depend on has a known security hole (CVE-2024-7254). Fix: Update that package to its patched version.
-
Worth fixing CVE-2022-3171 protobuf-java: timeout in parser leads to DoS
tensorflow/java/maven/pom.xml
A package you depend on has a known security hole (CVE-2022-3171). Fix: Update that package to its patched version.
-
Worth fixing CVE-2021-22569 protobuf-java: potential DoS in the parsing procedure for binary data
tensorflow/java/maven/pom.xml
A package you depend on has a known security hole (CVE-2021-22569). Fix: Update that package to its patched version.
-
Worth fixing CVE-2022-3509 protobuf-java: Textformat parsing issue leads to DoS
tensorflow/java/maven/pom.xml
A package you depend on has a known security hole (CVE-2022-3509). Fix: Update that package to its patched version.
-
Worth fixing CVE-2022-3510 protobuf-java: Message-Type Extensions parsing issue leads to DoS
tensorflow/java/maven/pom.xml
A package you depend on has a known security hole (CVE-2022-3510). Fix: Update that package to its patched version.