PT-2024-5198 · Dell+1 · Dell Data Lakehouse+1

Published

2024-07-18

·

Updated

2024-07-19

·

CVE-2024-38302

CVSS v3.1

6.8

Medium

VectorAV:A/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Dell Data Lakehouse version 1.0.0.0
Description: The issue is related to a Missing Encryption of Sensitive Data vulnerability in the DDAE (Starburst) component. This could allow a low-privileged attacker with adjacent network access to potentially exploit the vulnerability, leading to information disclosure. The vulnerability is associated with a lack of encryption measures for data, which could enable a remote attacker to disclose protected information.
Recommendations: For Dell Data Lakehouse version 1.0.0.0, consider implementing encryption for sensitive data in the DDAE (Starburst) component to prevent information disclosure. As a temporary workaround, restrict access to sensitive data until a proper encryption mechanism is in place.

Fix

Missing Encryption of Sensitive Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-05755
CVE-2024-38302

Affected Products

Ddae
Dell Data Lakehouse