Pinot Apache Pinot

Do you want an email whenever new security vulnerabilities are reported in Apache Pinot?

By the Year

In 2024 there have been 0 vulnerabilities in Apache Pinot . Pinot did not have any published security vulnerabilities last year.

Year Vulnerabilities Average Score
2024 0 0.00
2023 0 0.00
2022 2 8.65
2021 0 0.00
2020 0 0.00
2019 0 0.00
2018 0 0.00

It may take a day or so for new Pinot vulnerabilities to show up in the stats or in the list of recent security vulnerabilties. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Apache Pinot Security Vulnerabilities

In 0.10.0 or older versions of Apache Pinot

CVE-2022-26112 9.8 - Critical - September 23, 2022

In 0.10.0 or older versions of Apache Pinot, Pinot query endpoint and realtime ingestion layer has a vulnerability in unprotected environments due to a groovy function support. In order to avoid this, we disabled the groovy function support by default from Pinot release 0.11.0. See https://docs.pinot.apache.org/basics/releases/0.11.0

In 0.9.3 or older versions of Apache Pinot segment upload path allowed segment directories to be imported into pinot tables

CVE-2022-23974 7.5 - High - April 05, 2022

In 0.9.3 or older versions of Apache Pinot segment upload path allowed segment directories to be imported into pinot tables. In pinot installations that allow open access to the controller a specially crafted request can potentially be exploited to cause disruption in pinot service. Pinot release 0.10.0 fixes this. See https://docs.pinot.apache.org/basics/releases/0.10.0

Stack Exhaustion

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Apache Pinot or by Apache? Click the Watch button to subscribe.

Apache
Vendor

Apache Pinot
Product

subscribe