云虫漏洞情报

CVE-2026-82306 - StarRocks through 4.0.13 contains an information disclosure vulnerability in the query_detail endpoint that returns unfiltered query history for all users. Authenticated attackers with low privileges can access full SQL text, execution plans, and profiling data from every query executed by other users, including statements containing credentials. - 漏洞详情

漏洞编号:CVE-2026-82306

风险等级:中危

漏洞来源:CVE

CVE 编号:CVE-2026-82306

CNNVD 编号:-

厂商/产品:- / -

影响范围:-

CWE:CWE-200

发布/更新时间:2026-08-28 / 2026-08-28

漏洞描述

StarRocks through 4.0.13 contains an information disclosure vulnerability in the query_detail endpoint that returns unfiltered query history for all users. Authenticated attackers with low privileges can access full SQL text, execution plans, and profiling data from every query executed by other users, including statements containing credentials.

相关链接

相关漏洞

« 返回首页