Lucene search

K
cvelistApacheCVELIST:CVE-2023-49198
HistoryAug 21, 2024 - 9:37 a.m.

CVE-2023-49198 Apache SeaTunnel Web: Arbitrary file read vulnerability

2024-08-2109:37:57
CWE-552
apache
www.cve.org
4
cve-2023-49198
apache seatunnel
web vulnerability
fix available
mysql server
upgrade
version 1.0.1

EPSS

0.001

Percentile

34.8%

Mysql security vulnerability in Apache SeaTunnel.

Attackers can read files on the MySQL server by modifying the information in the MySQL URL

allowLoadLocalInfile=true&allowUrlInLocalInfile=true&allowLoadLocalInfileInPath=/&maxAllowedPacket=655360
This issue affects Apache SeaTunnel: 1.0.0.

Users are recommended to upgrade to version [1.0.1], which fixes the issue.

CNA Affected

[
  {
    "collectionURL": "https://repo.maven.apache.org/maven2",
    "defaultStatus": "unaffected",
    "product": "Apache SeaTunnel Web",
    "vendor": "Apache Software Foundation",
    "versions": [
      {
        "status": "affected",
        "version": "1.0.0",
        "versionType": "maven"
      }
    ]
  }
]

EPSS

0.001

Percentile

34.8%

Related for CVELIST:CVE-2023-49198