Логотип exploitDog
bind:CVE-2024-24565
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-24565

Количество 2

Количество 2

nvd логотип

CVE-2024-24565

около 2 лет назад

CrateDB is a distributed SQL database that makes it simple to store and analyze massive amounts of data in real-time. There is a COPY FROM function in the CrateDB database that is used to import file data into database tables. This function has a flaw, and authenticated attackers can use the COPY FROM function to import arbitrary file content into database tables, resulting in information leakage. This vulnerability is patched in 5.3.9, 5.4.8, 5.5.4, and 5.6.1.

CVSS3: 5.7
EPSS: Высокий
github логотип

GHSA-475g-vj6c-xf96

около 2 лет назад

CrateDB database has an arbitrary file read vulnerability

CVSS3: 5.7
EPSS: Высокий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-24565

CrateDB is a distributed SQL database that makes it simple to store and analyze massive amounts of data in real-time. There is a COPY FROM function in the CrateDB database that is used to import file data into database tables. This function has a flaw, and authenticated attackers can use the COPY FROM function to import arbitrary file content into database tables, resulting in information leakage. This vulnerability is patched in 5.3.9, 5.4.8, 5.5.4, and 5.6.1.

CVSS3: 5.7
84%
Высокий
около 2 лет назад
github логотип
GHSA-475g-vj6c-xf96

CrateDB database has an arbitrary file read vulnerability

CVSS3: 5.7
84%
Высокий
около 2 лет назад

Уязвимостей на страницу