PkgRadar

Maven · repo1.maven.org

com.alibaba.polardbx:polardbx-connector-java

Shell Credential File Read, Java Base64 Combo, Java Unsafe Deserialize +2 more

Why PkgRadar flagged 2.2.15

SeveritySignalEvidence
highShell Credential File Readcom/alibaba/polardbx/core/cj/protocol/ExportControlled.java
mediumJava Base64 Combocom/alibaba/polardbx/core/cj/protocol/ExportControlled.java
mediumJava Unsafe Deserializecom/alibaba/polardbx/core/cj/jdbc/result/ResultSetImpl.java
mediumJava Process Spawncom/alibaba/polardbx/core/cj/admin/ServerController.java
mediumJava Static Init Side Effectcom/alibaba/polardbx/core/cj/protocol/a/NativeProtocol.java
mediumJava Static Init Side Effectcom/alibaba/polardbx/core/cj/protocol/ExportControlled.java

Showing signal labels only. Sign in to view the exact matched indicators for each finding.

Scanned versions

VersionVerdictScoreScanned (UTC)
2.2.15High risk1242026-06-26

Block this in CI

PkgRadar gates com.alibaba.polardbx:polardbx-connector-java (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem maven com.alibaba.polardbx:[email protected]