Skip to content

Gpfdist contains file path traversal vulnerability

Low
divyabhargov published GHSA-hqh5-m87w-57w2 Nov 17, 2021

Package

gpfdist (Greenplum)

Affected versions

< 6.14.0

Patched versions

6.14.0
gpfdist (test)
< 5.28.6
5.28.6

Description

Impact

In versions of Greenplum database prior to 5.28.6 and 6.14.0, greenplum database contains a file path traversal vulnerability leading to information disclosure from the file system . A malicious user can read/write information from the file system using this vulnerability.

Patches

Greenplum 5.28.0 and 6.14.0 have fixed this issue.
[5X] ca36e54
[6X] a25b81d

Credits

Thanks to Liu Wei of ZTE Cybersecurity Lab for reporting this issue to us.

Severity

Low

CVE ID

CVE-2021-22028

Weaknesses

No CWEs