org.graalvm.sdk:graal-sdk@21.3.12 vulnerabilities

  • latest version

    24.2.0

  • latest non vulnerable version

  • first published

    6 years ago

  • latest version published

    1 months ago

  • licenses detected

  • package registry

  • Direct Vulnerabilities

    Known vulnerabilities in the org.graalvm.sdk:graal-sdk package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Signed to Unsigned Conversion Error

    org.graalvm.sdk:graal-sdk is a high-performance JDK distribution designed to accelerate the execution of applications written in Java and other JVM languages along with support for JavaScript, Ruby, Python, and a number of other popular languages.

    Affected versions of this package are vulnerable to Signed to Unsigned Conversion Error through the use of multiple protocols. An attacker can compromise accessible data and perform unauthorized update, insert, or delete operations by exploiting APIs in the specified component, typically through a web service which supplies data to these APIs.

    Note:

    This is only exploitable if Java deployments load and run untrusted code from the internet and rely on the Java sandbox for security.

    How to fix Signed to Unsigned Conversion Error?

    Upgrade org.graalvm.sdk:graal-sdk to version 20.3.17, 21.3.13 or higher.

    [,20.3.17)[21.0.0,21.3.13)