PT-2022-16378 · Apache · Apache Pinot

Bubblegumkk

+2

·

Published

2022-04-05

·

Updated

2022-04-15

·

CVE-2022-23974

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Apache Pinot versions 0.9.3 and earlier
Description The issue allows segment directories to be imported into Pinot tables through the segment upload path in Apache Pinot. In installations with open access to the controller, a specially crafted request can potentially disrupt the Pinot service.
Recommendations For Apache Pinot versions 0.9.3 and earlier, update to Pinot release 0.10.0 to fix the issue.

Fix

Uncontrolled Recursion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-23974
GHSA-29F8-Q7MF-7CQJ

Affected Products

Apache Pinot