Skip to content

Commit 9204c13

Browse files
authored
docs: update CVEs fixed on 3.0.2 and 2.1.3 (apache#26308)
1 parent c288c68 commit 9204c13

File tree

1 file changed

+16
-1
lines changed

1 file changed

+16
-1
lines changed

docs/docs/security/cves.mdx

+16-1
Original file line numberDiff line numberDiff line change
@@ -4,15 +4,30 @@ hide_title: true
44
sidebar_position: 2
55
---
66

7+
#### Version 3.0.2, 2.1.3
8+
9+
| CVE | Title | Affected |
10+
|:---------------|:------------------------------------------------------------|---------------------------:|
11+
| CVE-2023-46104 | Allows for uncontrolled resource consumption via a ZIP bomb | < 2.1.3, >= 3.0.0, < 3.0.2 |
12+
| CVE-2023-49736 | SQL Injection on where_in JINJA macro | < 2.1.3, >= 3.0.0, < 3.0.2 |
13+
| CVE-2023-49734 | Privilege Escalation Vulnerability | < 2.1.3, >= 3.0.0, < 3.0.2 |
14+
15+
716
#### Version 3.0.0
817

918
| CVE | Title | Affected |
1019
|:---------------|:------------------------------------------------------------------------|---------:|
1120
| CVE-2023-42502 | Open Redirect Vulnerability | < 3.0.0 |
12-
| CVE-2023-42504 | Lack of rate limiting allows for possible denial of service | < 3.0.0 |
1321
| CVE-2023-42505 | Sensitive information disclosure on db connection details | < 3.0.0 |
1422

1523

24+
#### Version 2.1.3
25+
26+
| CVE | Title | Affected |
27+
|:---------------|:------------------------------------------------------------------------|---------:|
28+
| CVE-2023-42504 | Lack of rate limiting allows for possible denial of service | < 2.1.3 |
29+
30+
1631
#### Version 2.1.2
1732

1833
| CVE | Title | Affected |

0 commit comments

Comments
 (0)