Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qj9p-jvmw-82rh

Опубликовано: 25 сент. 2022
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

Apache Pinot has Groovy Function support enabled by default

Pinot allows you to run any function using Apache Groovy scripts. In versions prior to 0.10.0, Pinot query endpoint and realtime ingestion layer has a vulnerability in unprotected environments due to groovy function support being enabled by default. This issue has been fixed by making function support disabled by default, in version 0.11.0. A potential workaround is to disable groovy script support.

Пакеты

Наименование

org.apache.pinot:pinot

maven
Затронутые версииВерсия исправления

< 0.11.0

0.11.0

EPSS

Процентиль: 82%
0.01769
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 9.8
nvd
больше 3 лет назад

In 0.10.0 or older versions of Apache Pinot, Pinot query endpoint and realtime ingestion layer has a vulnerability in unprotected environments due to a groovy function support. In order to avoid this, we disabled the groovy function support by default from Pinot release 0.11.0. See https://docs.pinot.apache.org/basics/releases/0.11.0

EPSS

Процентиль: 82%
0.01769
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-94