CVE-2022-23974
Dashboard / Vulnerabilities / CVE-2022-23974
Summary: Pinot segment push endpoint has a vulnerability in unprotected environments
Details: In 0.9.3 or older versions of Apache Pinot segment upload path allowed segment directories to be imported into pinot tables. In pinot installations that allow open access to the controller a specially crafted request can potentially be exploited to cause disruption in pinot service. Pinot release 0.10.0 fixes this. See https://docs.pinot.apache.org/basics/releases/0.10.0
References: https://lists.apache.org/thread/3dk8pf1n02p8oj2j3czbtchyjsf8khwr, https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/23xxx/CVE-2022-23974.json, https://nvd.nist.gov/vuln/detail/CVE-2022-23974
Affected packages
Package
Name:
Purl:
Affected ranges
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
