S4E just found a medium-severity finding from self signed ssl certificate detection
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Oct 8, 2024

CVE-2024-24565 Scanner

CVE-2024-24565 Scanner - Arbitrary File Read vulnerability in CrateDB

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.5k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-24565
6.5
CVSSmedium
Exploitable remotely over the internet · low-privilege account sufficient · user interaction needed.

CrateDB is a distributed SQL database that makes it simple to store and analyze massive amounts of data in real-time. There is a COPY FROM function in the CrateDB database that is used to import file data into database tables. This function has a flaw, and authenticated attackers can use the COPY FROM function to import arbitrary file content into database tables, resulting in information leakage. This vulnerability is patched in 5.3.9, 5.4.8, 5.5.4, and 5.6.1.

Attack Vector
Network
Privileges Req.
Low
User Interaction
Required
Affected
crateby crate
< 5.3.9
cratedbby cratedb
AFFECTED< 5.3.9SAFE ✓≥ 5.3.9
Updated Aug 22, 2026View on NVD →
Detail

CrateDB is a distributed SQL database tailored for real-time processing, allowing businesses to handle vast data volumes efficiently. It caters to organizations requiring swift data analytics and seamless integration across applications. CrateDB stands out for its ability to manage structured and unstructured data, offering powerful data ingestion and visualization features. It's widely used in IoT applications due to its scalability and high availability. The platform helps developers easily implement complex queries, providing rapid data insights. With its flexible setup, CrateDB supports cloud-based and on-premises implementations for diverse business needs.

The Arbitrary File Read vulnerability in CrateDB arises from insufficient input validation, leading to potential data leaks. Attackers could exploit the vulnerability by importing files arbitrarily through the COPY FROM function. This function was intended to facilitate data importation into tables; however, it exposes unauthorized file access points. The flaw specifically permits unauthorized file reads, including sensitive configuration files. Such vulnerabilities allow attackers to bypass normal access controls, thereby compromising data confidentiality. Exploits require authentication, making it crucial for environments with exposed CrateDB instances.

Technical exploitation of this vulnerability involves utilizing SQL commands to exploit the COPY FROM function. The vulnerability primarily targets the endpoint configured to handle data import requests. During an attack, crafted SQL statements are used to create tables and import data from sensitive file paths, such as '/etc/passwd'. The technique is reliant on misconfigured settings or insufficient validation of file paths within the CrateDB SQL command execution. Properly monitoring network traffic for abnormal sequences or unauthorized commands can be critical in identifying attempts at exploitation.

If exploited, the Arbitrary File Read vulnerability could expose confidential data stored in accessible files within the database's environment. It could lead to unauthorized data retrieval, which could then be leveraged for further attacks, such as privilege escalation or lateral movement within a network. The breach of sensitive information might result in reputational damage and violation of privacy regulations, necessitating immediate mitigation strategies. Additionally, exploited environments could suffer from data integrity issues, affecting business operations and decision-making processes.

REFERENCES

Solution Advice
  • Implement strict access controls and restrict SQL command execution to authorized users.
  • Regularly update CrateDB to the latest version to apply security patches and fixes.
  • Conduct routine security assessments and vulnerability scans in the database environment.
  • Monitor database logs for unusual activities or access patterns indicative of a breach.
  • Ensure backups are secure and regularly tested to minimize data loss risks.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.