Authentication Bypass Vulnerability in Apache Pinot
CVE-2024-56325
What is CVE-2024-56325?
An authentication bypass vulnerability exists in Apache Pinot that allows malicious actors to add new users without authentication. This occurs when requests are sent to specific endpoints that do not enforce the required authentication checks. As a result, an attacker can submit a specially crafted POST request to gain unauthorized access, thereby enabling the control of Pinot. This significant flaw underscores the need for proper validation mechanisms and access controls within the application to prevent unauthorized user creation and privilege escalation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Apache Pinot 0 < 1.3
References
EPSS Score
30% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved