CVE-2023-49198

Severity
7.5HIGH
EPSS
0.3%
top 46.25%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 21

Description

Mysql security vulnerability in Apache SeaTunnel. Attackers can read files on the MySQL server by modifying the information in the MySQL URL allowLoadLocalInfile=true&allowUrlInLocalInfile=true&allowLoadLocalInfileInPath=/&maxAllowedPacket=655360 This issue affects Apache SeaTunnel: 1.0.0. Users are recommended to upgrade to version [1.0.1], which fixes the issue.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

🔴Vulnerability Details

3
CVEList
Apache SeaTunnel Web: Arbitrary file read vulnerability2024-08-21
GHSA
Apache SeaTunnel SQL Injection vulnerability2024-08-21
OSV
Apache SeaTunnel SQL Injection vulnerability2024-08-21
CVE-2023-49198 (HIGH CVSS 7.5) | Mysql security vulnerability in Apa | cvebase.io