Security Advisory

CVE-2023-49198

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2024-08-21 09:37:57
Last updated 2024-08-23 13:04:21
Assigner apache
State PUBLISHED

Description

Mysql security vulnerability in Apache SeaTunnel. Attackers can read files on the MySQL server by modifying the information in the MySQL URL allowLoadLocalInfile=true&allowUrlInLocalInfile=true&allowLoadLocalInfileInPath=/&maxAllowedPacket=655360 This issue affects Apache SeaTunnel: 1.0.0. Users are recommended to upgrade to version [1.0.1], which fixes the issue.