Lucene search

K
cveApacheCVE-2022-26112
HistorySep 23, 2022 - 8:15 a.m.

CVE-2022-26112

2022-09-2308:15:08
apache
web.nvd.nist.gov
47
cve-2022-26112
apache pinot
vulnerability
groovy function
security
nvd
apache pinot 0.11.0

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.3

Confidence

High

EPSS

0.002

Percentile

55.6%

In 0.10.0 or older versions of Apache Pinot, Pinot query endpoint and realtime ingestion layer has a vulnerability in unprotected environments due to a groovy function support. In order to avoid this, we disabled the groovy function support by default from Pinot release 0.11.0. See https://docs.pinot.apache.org/basics/releases/0.11.0

Affected configurations

Nvd
Vulners
Node
apachepinotRange<0.11.0
VendorProductVersionCPE
apachepinot*cpe:2.3:a:apache:pinot:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Apache Pinot",
    "vendor": "Apache Software Foundation",
    "versions": [
      {
        "lessThanOrEqual": "0.10.0",
        "status": "affected",
        "version": "Apache Pinot",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.3

Confidence

High

EPSS

0.002

Percentile

55.6%

Related for CVE-2022-26112