CVE-2025-46690

Ververica Platform 2.14.0 allows low-privileged users to access SQL connectors via a direct namespaces/default/formats request.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ververica:ververica_platform:2.14.0:*:*:*:*:*:*:*

History

12 May 2025, 19:31

Type Values Removed Values Added
First Time Ververica
Ververica ververica Platform
References () https://github.com/gozan10/cve/issues/18 - () https://github.com/gozan10/cve/issues/18 - Exploit, Issue Tracking
References () https://github.com/ververica/ververica-platform-playground - () https://github.com/ververica/ververica-platform-playground - Product
References () https://www.ververica.com - () https://www.ververica.com - Product
CPE cpe:2.3:a:ververica:ververica_platform:2.14.0:*:*:*:*:*:*:*

28 Apr 2025, 17:15

Type Values Removed Values Added
Summary
  • (es) Ververica Platform 2.14.0 permite que usuarios con bajos privilegios accedan a conectores SQL a través de una solicitud directa de espacios de nombres/predeterminados/formatos.
References () https://github.com/gozan10/cve/issues/18 - () https://github.com/gozan10/cve/issues/18 -

27 Apr 2025, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-27 22:15

Updated : 2025-05-12 19:31


NVD link : CVE-2025-46690

Mitre link : CVE-2025-46690

CVE.ORG link : CVE-2025-46690


JSON object : View

Products Affected

ververica

  • ververica_platform
CWE
CWE-425

Direct Request ('Forced Browsing')