PT-2026-68455 · Apache · Apache Polaris
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Apache Polaris (affected versions not specified)
Description
An authenticated principal with permissions to register tables or views can cause the system to use catalog storage credentials to read a selected Iceberg metadata file before verifying if the file is within allowed storage locations. This occurs when the system fails to consistently validate storage locations during registration. If the underlying credentials have access to objects outside the defined boundary, limited information from those objects may be disclosed. Additionally, the system may accept registration metadata within an allowed location that references storage locations outside the allowed boundary, although this does not trigger a read of the external locations during registration. This issue requires a deployment using S3 credential vending and an object outside the allowed locations that the catalog credentials can access.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Polaris