Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-29f8-q7mf-7cqj

Опубликовано: 06 апр. 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Logic error in Apache Pinot

In 0.9.3 or older versions of Apache Pinot segment upload path allowed segment directories to be imported into pinot tables. In pinot installations that allow open access to the controller a specially crafted request can potentially be exploited to cause disruption in pinot service. Pinot release 0.10.0 fixes this. See https://docs.pinot.apache.org/basics/releases/0.10.0

Пакеты

Наименование

org.apache.pinot:pinot

maven
Затронутые версииВерсия исправления

< 0.10.0

0.10.0

EPSS

Процентиль: 88%
0.03726
Низкий

7.5 High

CVSS3

Дефекты

CWE-674

Связанные уязвимости

CVSS3: 7.5
nvd
больше 3 лет назад

In 0.9.3 or older versions of Apache Pinot segment upload path allowed segment directories to be imported into pinot tables. In pinot installations that allow open access to the controller a specially crafted request can potentially be exploited to cause disruption in pinot service. Pinot release 0.10.0 fixes this. See https://docs.pinot.apache.org/basics/releases/0.10.0

EPSS

Процентиль: 88%
0.03726
Низкий

7.5 High

CVSS3

Дефекты

CWE-674