CVE-2024-24565: CrateDB数据库任意文件读取漏洞

CVE-2024-24565: CrateDB数据库任意文件读取漏洞-渗透云记 - 专注于网络安全与技术分享
CVE-2024-24565: CrateDB数据库任意文件读取漏洞
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2024-24565: CrateDB数据库任意文件读取漏洞

漏洞描述

CrateDB is a distributed SQL database that makes it simple to store and analyze massive amounts of data in real-time. There is a COPY FROM function in the CrateDB database that is used to import file data into database tables. This function has a flaw, and authenticated attackers can use the COPY FROM function to import arbitrary file content into database tables, resulting in information leakage. This vulnerability is patched in 5.3.9, 5.4.8, 5.5.4, and 5.6.1.

fofa: title="CrateDB"

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享