CVE-2024-37309
- EPSS 0.25%
- Veröffentlicht 13.06.2024 14:15:13
- Zuletzt bearbeitet 04.09.2025 19:11:21
CrateDB is a distributed SQL database. A high-risk vulnerability has been identified in versions prior to 5.7.2 where the TLS endpoint (port 4200) permits client-initiated renegotiation. In this scenario, an attacker can exploit this feature to repea...
CVE-2024-24565
- EPSS 82.89%
- Veröffentlicht 30.01.2024 17:15:12
- Zuletzt bearbeitet 21.11.2024 08:59:25
CrateDB is a distributed SQL database that makes it simple to store and analyze massive amounts of data in real-time. There is a COPY FROM function in the CrateDB database that is used to import file data into database tables. This function has a fla...
CVE-2023-51982
- EPSS 0.04%
- Veröffentlicht 30.01.2024 01:15:59
- Zuletzt bearbeitet 29.05.2025 15:15:26
CrateDB 5.5.1 is contains an authentication bypass vulnerability in the Admin UI component. After configuring password authentication and_ Local_ In the case of an address, identity authentication can be bypassed by setting the X-Real IP request head...