Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2024-41672— DuckDB: sniff_csv provides filesystem access even when enable_external_access is disabled

Quick assessment

Affected
duckdb duckdb
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

DuckDB是DuckDB开源的一个进程内 SQL OLAP 数据库管理系统。 DuckDB 1.0.0及之前的版本存在安全漏洞,该漏洞源于即使在enable_external_access被禁用的情况下sniff_csv也能提供文件系统访问,从而导致攻击者能够访问文件系统。

CVSS 7.5 · High EPSS 0.81% · P56
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2024-41672

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
DuckDB: sniff_csv provides filesystem access even when enable_external_access is disabled
Source: CVE Program / CVE List V5
Vulnerability Description
DuckDB is a SQL database management system. In versions 1.0.0 and prior, content in filesystem is accessible for reading using `sniff_csv`, even with `enable_external_access=false`. This vulnerability provides an attacker with access to filesystem even when access is expected to be disabled and other similar functions do NOT provide access. There seem to be two vectors to this vulnerability. First, access to files that should otherwise not be allowed. Second, the content from a file can be read (e.g. `/etc/hosts`, `proc/self/environ`, etc) even though that doesn't seem to be the intent of the sniff_csv function. A fix for this issue is available in commit c9b7c98aa0e1cd7363fe8bb8543a95f38e980d8a and is expected to be part of version 1.1.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
信息暴露
Source: CVE Program / CVE List V5
Vulnerability Title
DuckDB 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
DuckDB是DuckDB开源的一个进程内 SQL OLAP 数据库管理系统。 DuckDB 1.0.0及之前的版本存在安全漏洞,该漏洞源于即使在enable_external_access被禁用的情况下sniff_csv也能提供文件系统访问,从而导致攻击者能够访问文件系统。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
duckdb duckdb <= 1.0.0 -

II. Public POCs for CVE-2024-41672

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2024-41672

请登录查看更多情报信息。

Patches & Fixes for CVE-2024-41672 (2)

Vendor Advisories for CVE-2024-41672 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2024-41672

No comments yet


Leave a comment