Beveiligingsadvies

CVE-2024-45198

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2025-04-03 00:00:00
Laatst bijgewerkt 2025-04-04 15:25:07
Toegewezen door mitre
CVSS-score 8.8
Status PUBLISHED

Beschrijving

insightsoftware Spark JDBC 2.6.21 has a remote code execution vulnerability. Attackers can inject malicious parameters into the JDBC URL, triggering JNDI injection during the process when the JDBC Driver uses this URL to connect to the database. This can further lead to remote code execution.