Pinot
Apache · 4 CVEs
CVE-2024-56325
CRITICAL
Apache Pinot: Authentication bypass issue. If the path does not contain / and contain . authentication is not required
Apr 1, 2025
CVE-2024-39676
HIGH
Apache Pinot: Unauthorized endpoint exposed sensitive information
Jul 24, 2024
CVE-2022-26112
CRITICAL
Pinot query endpoint and the realtime ingestion layer has a vulnerability in unprotected environments due to a groovy f…
Sep 23, 2022
CVE-2022-23974
HIGH
Pinot segment push endpoint has a vulnerability in unprotected environments
Apr 5, 2022
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2024-56325 | Apache Pinot: Authentication bypass issue. If the path does not contain / and contain . authentication is not required | CRITICAL | 80.21% | Apr 1, 2025 |
| CVE-2024-39676 | Apache Pinot: Unauthorized endpoint exposed sensitive information | HIGH | 0.85% | Jul 24, 2024 |
| CVE-2022-26112 | Pinot query endpoint and the realtime ingestion layer has a vulnerability in unprotected environments due to a groovy function support | CRITICAL | 1.60% | Sep 23, 2022 |
| CVE-2022-23974 | Pinot segment push endpoint has a vulnerability in unprotected environments | HIGH | 2.08% | Apr 5, 2022 |
Showing 1 to 4 of 4 CVEs