Filtered by vendor Apache Subscriptions
Filtered by product Gobblin Subscriptions
Total 2 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2021-36152 1 Apache 1 Gobblin 2022-02-09 9.8 Critical
Apache Gobblin trusts all certificates used for LDAP connections in Gobblin-as-a-Service. This affects versions <= 0.15.0. Users should update to version 0.16.0 which addresses this issue.
CVE-2021-36151 1 Apache 1 Gobblin 2022-02-09 5.5 Medium
In Apache Gobblin, the Hadoop token is written to a temp file that is visible to all local users on Unix-like systems. This affects versions <= 0.15.0. Users should update to version 0.16.0 which addresses this issue.