PT-2026-45695 · Apache · Apache Calcite
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Apache Calcite versions 1.5.0 through 1.41
Description
An unsafe reflection issue exists where externally-controlled input can be used to select classes or code. Specifically, a user-controlled model can load arbitrary classes, which may lead to remote code execution.
Recommendations
Upgrade to version 1.42.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Calcite