# High severity vulnerabilities in datomic transactor

**URL:** <https://forum.datomic.com/t/high-severity-vulnerabilities-in-datomic-transactor/2144>\
**Category:** Datomic Pro\
**Created:** [October 21, 2022, 5:45pm UTC](https://forum.datomic.com/t/high-severity-vulnerabilities-in-datomic-transactor/2144 "2022-10-21T17:45:53Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![jasonjckn](https://sea2.discourse-cdn.com/flex016/user_avatar/forum.datomic.com/jasonjckn/32/540_2.png) [@jasonjckn](https://forum.datomic.com/u/jasonjckn)\
**Post date:** [October 21, 2022, 5:45pm UTC](https://forum.datomic.com/t/high-severity-vulnerabilities-in-datomic-transactor/2144/1 "2022-10-21T17:45:53Z")

</div>

We’re attempting to deploy Datomic, and we’ve built an application on top of it, but in order to go to production, we have strict requirements of zero high severity vulnerabilities as identified by the National Vulnerability Database.

According to our scans of the Datomic Transactor (version=1.0.6397) we’ve identified at least 10 high severity vulnerabilities, including at least one zero-day exploit. They are as follows: **CVE-2020-27853, CVE-2021-41093, CVE-2022-33980** , **CVE-2021-42392, CVE-2022-23221, CVE-2022-40150, CVE-2022-40149** , **CVE-2022-31197, CVE-2022-21724, CVE-2022-42889.**

Is there any plan and/or timeline when these vulnerabilities will be resolved?  
Is there a security analysis available on why leave these unresolved is feasible in a production-grade setting.

Thank you!

---

<div class="post-metadata">

**Author:** ![Robert-Randolph](https://sea2.discourse-cdn.com/flex016/user_avatar/forum.datomic.com/robert-randolph/32/545_2.png) [@Robert-Randolph](https://forum.datomic.com/u/Robert-Randolph)\
**Post date:** [October 21, 2022, 6:54pm UTC](https://forum.datomic.com/t/high-severity-vulnerabilities-in-datomic-transactor/2144/2 "2022-10-21T18:54:33Z")

</div>

@jasonjckn Hello! We current have a support ticket created on the issue and have not received a response.

Could you check to see if you received the reply and provide the information requested in the ticket?

We do not currently believe these CVE’s affect the product, however further research is required after reviewing the provided information.

-Robert Randolph

---

<div class="post-metadata">

**Author:** ![jasonjckn](https://sea2.discourse-cdn.com/flex016/user_avatar/forum.datomic.com/jasonjckn/32/540_2.png) [@jasonjckn](https://forum.datomic.com/u/jasonjckn)\
**Post date:** [October 21, 2022, 11:55pm UTC](https://forum.datomic.com/t/high-severity-vulnerabilities-in-datomic-transactor/2144/3 "2022-10-21T23:55:05Z")

</div>

> Could you check to see if you received the reply and provide the information requested in the ticket?

just checked, haven’t gotten a reply yet. let me know when you send it.

---

<div class="post-metadata">

**Author:** ![jaret](https://sea2.discourse-cdn.com/flex016/user_avatar/forum.datomic.com/jaret/32/45_2.png) [@jaret](https://forum.datomic.com/u/jaret)\
**Post date:** [October 22, 2022, 12:40am UTC](https://forum.datomic.com/t/high-severity-vulnerabilities-in-datomic-transactor/2144/4 "2022-10-22T00:40:46Z")

</div>

Hi Jason,

We have sent you two replies on the case. Can you login to Zendesk to confirm here: [https://support.cognitect.com/hc/en-us](https://support.cognitect.com/hc/en-us)

Or can you check your spam to confirm replies from [support@datomic.com](mailto:support@datomic.com) are allowed?

I am happy to share here that we have requested exactly what scanner you used to produce these results and what did you point them at/how did you run the scanner?

Thanks,  
Jaret

---

<div class="post-metadata">

**Author:** ![jasonjckn](https://sea2.discourse-cdn.com/flex016/user_avatar/forum.datomic.com/jasonjckn/32/540_2.png) [@jasonjckn](https://forum.datomic.com/u/jasonjckn)\
**Post date:** [October 22, 2022, 12:58am UTC](https://forum.datomic.com/t/high-severity-vulnerabilities-in-datomic-transactor/2144/5 "2022-10-22T00:58:19Z")

</div>

I can see it now, my bad. I’ll reply on that thread from here on out - thanks!
