Gpfdist contains file path traversal vulnerability
Package
gpfdist
(Greenplum)
Affected versions
< 6.14.0
Patched versions
6.14.0
gpfdist
(test)
< 5.28.6
5.28.6
Impact
In versions of Greenplum database prior to 5.28.6 and 6.14.0, greenplum database contains a file path traversal vulnerability leading to information disclosure from the file system . A malicious user can read/write information from the file system using this vulnerability.
Patches
Greenplum 5.28.0 and 6.14.0 have fixed this issue.
[5X] ca36e54
[6X] a25b81d
Credits
Thanks to Liu Wei of ZTE Cybersecurity Lab for reporting this issue to us.