Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rm2v-wh2x-rj6w

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.9

Описание

An SQL injection vulnerability was found in Cloudera Data Science Workbench (CDSW) 1.4.0 through 1.4.2. This would allow any authenticated user to run arbitrary queries against CDSW's internal database. The database contains user contact information, encrypted CDSW passwords (in the case of local authentication), API keys, and stored Kerberos keytabs.

An SQL injection vulnerability was found in Cloudera Data Science Workbench (CDSW) 1.4.0 through 1.4.2. This would allow any authenticated user to run arbitrary queries against CDSW's internal database. The database contains user contact information, encrypted CDSW passwords (in the case of local authentication), API keys, and stored Kerberos keytabs.

EPSS

Процентиль: 75%
0.00865
Низкий

9.9 Critical

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 9.9
nvd
больше 6 лет назад

An SQL injection vulnerability was found in Cloudera Data Science Workbench (CDSW) 1.4.0 through 1.4.2. This would allow any authenticated user to run arbitrary queries against CDSW's internal database. The database contains user contact information, encrypted CDSW passwords (in the case of local authentication), API keys, and stored Kerberos keytabs.

EPSS

Процентиль: 75%
0.00865
Низкий

9.9 Critical

CVSS3

Дефекты

CWE-89