Dtstack

Taier

7 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.38%
  • Veröffentlicht 14.08.2026 00:15:08
  • Zuletzt bearbeitet 18.08.2026 02:17:25

A vulnerability was determined in DTStack Taier 1.4.0. Affected by this issue is the function FileUtils.deleteDirectory of the file ClusterController.java of the component Cluster Creation. This manipulation of the argument clusterName causes path tr...

Exploit
  • EPSS 0.42%
  • Veröffentlicht 14.08.2026 00:00:10
  • Zuletzt bearbeitet 14.08.2026 19:09:39

A vulnerability was found in DTStack Taier 1.4.0. Affected by this vulnerability is the function Paths.ge of the file FileChunkController.java of the component Chunk-Check Endpoint. The manipulation of the argument Name results in path traversal. The...

  • EPSS 0.4%
  • Veröffentlicht 13.08.2026 23:45:09
  • Zuletzt bearbeitet 14.08.2026 19:09:56

A vulnerability has been found in DTStack Taier 1.4.0. Affected is the function MultipartFile.getOriginalFilename of the file UploadController.java of the component Upload Controller. The manipulation of the argument File leads to path traversal. The...

Exploit
  • EPSS 0.4%
  • Veröffentlicht 09.06.2026 02:15:13
  • Zuletzt bearbeitet 23.07.2026 08:10:00

A vulnerability was determined in DTStack Taier up to 1.4.0. The affected element is the function preHandle of the file taier-data-develop/src/main/java/com/dtstack/taier/develop/interceptor/LoginInterceptor.java of the component Source Connection Te...

Exploit
  • EPSS 1.36%
  • Veröffentlicht 25.05.2026 07:15:09
  • Zuletzt bearbeitet 23.07.2026 11:10:00

A vulnerability has been found in DTStack Taier 1.4.0. This affects the function Runtime.exec of the component REST API. The manipulation of the argument sqlText leads to os command injection. The attack is possible to be carried out remotely. The ex...

  • EPSS 0.51%
  • Veröffentlicht 05.12.2024 20:15:22
  • Zuletzt bearbeitet 15.04.2026 00:35:42

DTStack Taier 1.4.0 allows remote attackers to specify the jobName parameter in the console listNames function to cause a SQL injection vulnerability

Exploit
  • EPSS 0.63%
  • Veröffentlicht 23.06.2023 12:15:09
  • Zuletzt bearbeitet 21.11.2024 07:57:35

An insecure permissions in /Taier/API/tenant/listTenant interface in DTStack Taier 1.3.0 allows attackers to view sensitive information via the getCookie method.