Aller au contenu

Fiche vulnérabilité

CVE-2024-28251 : faille élevée pinterest querybook (CVSS 7.3)

Description

Querybook is a Big Data Querying UI, combining collocated table metadata and a simple notebook interface. Querybook's datadocs functionality works by using a Websocket Server. The client talks to this WSS whenever updating/deleting/reading any cells as well as for watching the live status of query executions. Currently the CORS setting allows all origins, which could result in cross-site websocket hijacking and allow attackers to read/edit/remove datadocs of the user. This issue has been addressed in version 3.32.0. Users are advised to upgrade. There are no known workarounds for this vulnerability.

En bref

Sévérité
Élevée (CVSS 7.3)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Exploitation active
Non signalée par la CISA
Publication
14 mars 2024
Dernière mise à jour
17 juin 2026

Produits concernés

  • pinterest querybook

Références

Rechercher une autre vulnérabilité dans la base CVE