PT-2026-53168 · Undefined · Undefined
Publicado
2026-06-28
·
Atualizado
2026-06-28
·
CVE-2026-13512
CVSS v2.0
6.5
Média
| Vetor | AV:N/AC:L/Au:S/C:P/I:P/A:P |
A vulnerability was identified in Databend up to 1.2.881 on HTTP. This affects the function ClientSessionManager::state key of the file src/query/service/src/servers/http/v1/session/client session manager.rs of the component Tenant Handler. The manipulation leads to authorization bypass. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The pull request to fix this issue awaits acceptance.
Correção
Improper Authorization
IDOR
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Undefined