QID 982654
QID 982654: Java (maven) Security Update for org.apache.skywalking:oap-server (GHSA-grpf-gg7v-5g5h)
Only when using H2/MySQL/TiDB as Apache SkyWalking storage, there is a SQL injection vulnerability in the wildcard query cases.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-grpf-gg7v-5g5h for updates pertaining to this vulnerability.
Vendor References
- GHSA-grpf-gg7v-5g5h -
github.com/advisories/GHSA-grpf-gg7v-5g5h
CVEs related to QID 982654
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-grpf-gg7v-5g5h | org.apache.skywalking:oap-server |
|