Skip to main content

Vendor/product archive

apache / pinot CVEs

Beta · best-effort

4 CVEs tagged to apache / pinot2 Critical, 2 High, 0 Medium, 0 Low, 0 Unrated.

CVE-2024-56325

Published Apr 1, 2025

Authentication Bypass Issue If the path does not contain / and contain., authentication is not required. Expected Normal Request and Response Example curl -X POST -H "Content-T…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-39676

Published Jul 24, 2024

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Pinot. This issue affects Apache Pinot: from 0.1 before 1.0.0. Users are recommended to upgrad…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-26112

Published Sep 23, 2022

In 0.10.0 or older versions of Apache Pinot, Pinot query endpoint and realtime ingestion layer has a vulnerability in unprotected environments due to a groovy function support. In…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-23974

Published Apr 5, 2022

In 0.9.3 or older versions of Apache Pinot segment upload path allowed segment directories to be imported into pinot tables. In pinot installations that allow open access to the c…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1