Apache Pinot vulnerabilities

4 known vulnerabilities affecting apache/pinot.

Total CVEs
4
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH2

Vulnerabilities

Page 1 of 1
CVE-2024-56325CRITICALCVSS 9.8PoCfixed in 1.3.02025-04-01
CVE-2024-56325 [CRITICAL] CWE-288 CVE-2024-56325: Authentication Bypass Issue If the path does not contain / and contain., authentication is not requ Authentication Bypass Issue If the path does not contain / and contain., authentication is not required. Expected Normal Request and Response Example curl -X POST -H "Content-Type: application/json" -d {\"username\":\"hack2\",\"password\":\"hack\",\"component\":\"CONTROLLER\",\"role\":\"ADMIN\",\"tables\":[],\"permissions\":[],\"usernameWithCom
nvd
CVE-2024-39676HIGHCVSS 7.5≥ 0.1.0, < 1.0.02024-07-24
CVE-2024-39676 [HIGH] CWE-200 CVE-2024-39676: Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Pinot. This issu Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Pinot. This issue affects Apache Pinot: from 0.1 before 1.0.0. Users are recommended to upgrade to version 1.0.0 and configure RBAC, which fixes the issue. Details: When using a request to path “/appconfigs” to the controller, it can lead to the disclosure of sensit
nvd
CVE-2022-26112CRITICALCVSS 9.8fixed in 0.11.02022-09-23
CVE-2022-26112 [CRITICAL] CWE-94 CVE-2022-26112: In 0.10.0 or older versions of Apache Pinot, Pinot query endpoint and realtime ingestion layer has a In 0.10.0 or older versions of Apache Pinot, Pinot query endpoint and realtime ingestion layer has a vulnerability in unprotected environments due to a groovy function support. In order to avoid this, we disabled the groovy function support by default from Pinot release 0.11.0. See https://docs.pinot.apache.org/basics/releases/0.11.0
nvd
CVE-2022-23974HIGHCVSS 7.5fixed in 0.10.02022-04-05
CVE-2022-23974 [HIGH] CWE-674 CVE-2022-23974: In 0.9.3 or older versions of Apache Pinot segment upload path allowed segment directories to be imp In 0.9.3 or older versions of Apache Pinot segment upload path allowed segment directories to be imported into pinot tables. In pinot installations that allow open access to the controller a specially crafted request can potentially be exploited to cause disruption in pinot service. Pinot release 0.10.0 fixes this. See https://docs.pinot.apache.org/ba
nvd
Apache Pinot vulnerabilities | cvebase