谷歌云平台中 Google Cloud BigQuery 数据迁移服务(Data Transfer Service)在 2026 年 5 月 1 日之前的版本中,其 CData JDBC 驱动程序集成存在一个“不当输入验证”漏洞。该漏洞允许经过身份验证的攻击者通过精心构造的 JDBC 连接字符串参数,在连接器容器中实现远程代码执行,并利用这些参数在租户项目中提升权限。 该漏洞已于 2026 年 5 月 1 日修复,客户无需采取任何操作。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Google Cloud | BigQuery Data Transfer Service | < 2026-05-01 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Google Cloud | BigQuery Data Transfer Service | 0 ~ 2026-05-01 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet