Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8m84-h9hh-3cfh

Опубликовано: 21 авг. 2024
Источник: github
Github: Прошло ревью
CVSS4: 8.7
CVSS3: 7.5

Описание

Apache SeaTunnel SQL Injection vulnerability

Mysql security vulnerability in Apache SeaTunnel.

Attackers can read files on the MySQL server by modifying the information in the MySQL URL

allowLoadLocalInfile=true&allowUrlInLocalInfile=true&allowLoadLocalInfileInPath=/&maxAllowedPacket=655360 This issue affects Apache SeaTunnel: 1.0.0.

Users are recommended to upgrade to version [1.0.1], which fixes the issue.

Пакеты

Наименование

org.apache.seatunnel:seatunnel

maven
Затронутые версииВерсия исправления

= 1.0.0

1.0.1

EPSS

Процентиль: 53%
0.00305
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-552

Связанные уязвимости

CVSS3: 7.5
nvd
больше 1 года назад

Mysql security vulnerability in Apache SeaTunnel. Attackers can read files on the MySQL server by modifying the information in the MySQL URL allowLoadLocalInfile=true&allowUrlInLocalInfile=true&allowLoadLocalInfileInPath=/&maxAllowedPacket=655360 This issue affects Apache SeaTunnel: 1.0.0. Users are recommended to upgrade to version [1.0.1], which fixes the issue.

EPSS

Процентиль: 53%
0.00305
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-552