Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:37287
HistorySep 27, 2022 - 4:25 a.m.

Privilege Escalation

2022-09-2704:25:37
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
15
pinot-controller
privilege escalation
vulnerability
controllerconf.java
groovy functionality
table-level config
broker/controller config

EPSS

0.002

Percentile

55.6%

pinot-controller is vulnerable to privilege escalation. The vulnerability exists because the isDisableIngestionGroovy function of ControllerConf.java does not properly disable groovy functionality by default allowing an attacker to modify table-level config or broker/controller config to turn it on globally.

EPSS

0.002

Percentile

55.6%

Related for VERACODE:37287