CVE-2024-24565

Source
https://cve.org/CVERecord?id=CVE-2024-24565
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-24565.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-24565
Aliases
Published
2024-01-30T16:46:15.200Z
Modified
2026-07-22T02:51:03.934799Z
Severity
  • 5.7 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N CVSS Calculator
Summary
CrateDB database has an arbitrary file read vulnerability
Details

CrateDB is a distributed SQL database that makes it simple to store and analyze massive amounts of data in real-time. There is a COPY FROM function in the CrateDB database that is used to import file data into database tables. This function has a flaw, and authenticated attackers can use the COPY FROM function to import arbitrary file content into database tables, resulting in information leakage. This vulnerability is patched in 5.3.9, 5.4.8, 5.5.4, and 5.6.1.

Database specific
{
    "cwe_ids": [
        "CWE-22"
    ],
    "cna_assigner": "GitHub_M",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/24xxx/CVE-2024-24565.json"
}
References

Affected packages

Git / github.com/crate/crate

Affected ranges

Type
GIT
Repo
https://github.com/crate/crate
Events
Database specific
{
    "cpe": "cpe:2.3:a:cratedb:cratedb:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "5.3.9"
        },
        {
            "introduced": "5.4.0"
        },
        {
            "fixed": "5.4.8"
        },
        {
            "introduced": "5.5.0"
        },
        {
            "fixed": "5.5.4"
        },
        {
            "introduced": "5.6.0"
        },
        {
            "fixed": "5.6.1"
        }
    ],
    "source": [
        "CPE_RANGE",
        "REFERENCES"
    ]
}

Affected versions

0.*
0.0.6
0.0.7
0.0.8
0.1.0
0.1.1
0.10.1
0.10.2
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.17.0
0.17.1
0.17.2
0.17.3
0.18.1
0.18.2
0.18.3
0.18.4
0.18.5
0.18.6
0.19.0
0.19.1
0.19.10
0.19.11
0.19.12
0.19.13
0.19.14
0.19.2
0.19.3
0.19.4
0.19.5
0.19.6
0.19.7
0.19.8
0.19.9
0.2.0
0.2.1
0.20.0
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.1
0.22.0
0.22.1
0.22.2
0.23.1
0.23.2
0.24.0
0.25.0
0.26.0
0.27.0
0.28.0
0.29.0
0.3.0
0.31.0
0.32.0
0.32.1
0.32.2
0.33.0
0.34.0
0.35.0
0.35.1
0.35.2
0.35.3
0.35.4
0.36.0
0.36.2
0.36.3
0.37.0
0.37.1
0.38.0
0.39.0
0.4.0
0.41.0
0.42.0
0.43.0
0.45.0
0.46.0
0.47.0
0.49.0
0.5.0
0.6.0
0.7.0
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
2.*
2.2.0
2.3.0
2.3.1
2.3.2
3.*
3.0.0
3.0.1
3.1.0
3.2.0
4.*
4.0.0
4.1.0
4.2.0
4.2.1
4.3.0
4.4.0
4.5.0
4.6.0
4.7.0
4.8.0
5.*
5.0.0
5.1.0
5.2.0
5.3.0
5.3.1
5.3.2
5.3.3
5.3.4
5.3.5
5.3.6
5.3.7
5.3.8
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.4.5
5.4.6
5.4.7
5.5.0
5.5.1
5.5.2
5.5.3
5.6.0
Other
list

Database specific

vanir_signatures_modified
"2026-07-22T02:51:03Z"
vanir_signatures
[
    {
        "signature_type": "Line",
        "deprecated": false,
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "97948461499565271408548590638510619927",
                "318376211251726745464397517936514448672",
                "288295609735365733876469480918026961081",
                "245503503530420965823402586945597271114"
            ]
        },
        "signature_version": "v1",
        "source": "https://github.com/crate/crate/commit/14a336c33752db5b3a82146efb55c757d1d734f9",
        "id": "CVE-2024-24565-001a9e27",
        "target": {
            "file": "server/src/main/java/org/elasticsearch/Version.java"
        }
    },
    {
        "signature_type": "Line",
        "deprecated": false,
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "291384341192235036339690049907721375470",
                "317294145501829008644578113444358393284",
                "276684022130702841733302510083246495706",
                "329705170640763057666413726956731606832"
            ]
        },
        "signature_version": "v1",
        "source": "https://github.com/crate/crate/commit/4e857d675683095945dd524d6ba03e692c70ecd6",
        "id": "CVE-2024-24565-06680788",
        "target": {
            "file": "server/src/test/java/io/crate/execution/engine/collect/sources/FileCollectSourceTest.java"
        }
    },
    {
        "signature_type": "Line",
        "deprecated": false,
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "250450102683043739425720662710849902866",
                "173363420767489663500223931878685445170",
                "167174489652105061883034334346055350895",
                "295137479575845494766195031249073613483"
            ]
        },
        "signature_version": "v1",
        "source": "https://github.com/crate/crate/commit/ed23d5afa9c22960217db8dbf90e67461a1635bb",
        "id": "CVE-2024-24565-1200047e",
        "target": {
            "file": "server/src/main/java/org/elasticsearch/Version.java"
        }
    },
    {
        "signature_type": "Function",
        "deprecated": false,
        "digest": {
            "length": 903.0,
            "function_hash": "200275461560550862037259504860846582034"
        },
        "signature_version": "v1",
        "source": "https://github.com/crate/crate/commit/4e857d675683095945dd524d6ba03e692c70ecd6",
        "id": "CVE-2024-24565-177029a3",
        "target": {
            "function": "getIterator",
            "file": "server/src/main/java/io/crate/execution/engine/collect/sources/FileCollectSource.java"
        }
    },
    {
        "signature_type": "Function",
        "deprecated": false,
        "digest": {
            "length": 205.0,
            "function_hash": "209783443772821192477210440163459434127"
        },
        "signature_version": "v1",
        "source": "https://github.com/crate/crate/commit/4e857d675683095945dd524d6ba03e692c70ecd6",
        "id": "CVE-2024-24565-1974be85",
        "target": {
            "function": "it",
            "file": "server/src/test/java/io/crate/execution/engine/collect/files/FileReadingCollectorTest.java"
        }
    },
    {
        "signature_type": "Line",
        "deprecated": false,
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "51039015873055425942510269873983942882",
                "223690567670949502805279595495465831129",
                "96702808003505909244004435568643320214",
                "184105513226046550339035802610859750296"
            ]
        },
        "signature_version": "v1",
        "source": "https://github.com/crate/crate/commit/16e4caa314c190fa9a907ff3644949136e75d226",
        "id": "CVE-2024-24565-24f64f84",
        "target": {
            "file": "server/src/main/java/org/elasticsearch/Version.java"
        }
    },
    {
        "signature_type": "Line",
        "deprecated": false,
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "305143203435635942404857508664503336813",
                "220079053773570135100543441091983604738",
                "288555927952111190902307004249745987071"
            ]
        },
        "signature_version": "v1",
        "source": "https://github.com/crate/crate/commit/4e857d675683095945dd524d6ba03e692c70ecd6",
        "id": "CVE-2024-24565-295d702a",
        "target": {
            "file": "server/src/main/java/io/crate/exceptions/UnauthorizedException.java"
        }
    },
    {
        "signature_type": "Function",
        "deprecated": false,
        "digest": {
            "length": 1047.0,
            "function_hash": "230515388479631325366851466458582168821"
        },
        "signature_version": "v1",
        "source": "https://github.com/crate/crate/commit/4e857d675683095945dd524d6ba03e692c70ecd6",
        "id": "CVE-2024-24565-315757b6",
        "target": {
            "function": "test_consecutive_retries_will_not_result_in_duplicate_reads",
            "file": "server/src/test/java/io/crate/execution/engine/collect/files/FileReadingIteratorTest.java"
        }
    },
    {
        "signature_type": "Function",
        "deprecated": false,
        "digest": {
            "length": 1306.0,
            "function_hash": "13470321046301819237749895885175086846"
        },
        "signature_version": "v1",
        "source": "https://github.com/crate/crate/commit/4e857d675683095945dd524d6ba03e692c70ecd6",
        "id": "CVE-2024-24565-41e2dc62",
        "target": {
            "function": "test_iterator_closes_current_reader_on_io_error",
            "file": "server/src/test/java/io/crate/execution/engine/collect/files/FileReadingIteratorTest.java"
        }
    },
    {
        "signature_type": "Line",
        "deprecated": false,
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "168835139634499239807948756668170119760",
                "167570060385755614107871435889426142589",
                "84156736485957732666820674766276576661",
                "186510035630312388699352801541534051477"
            ]
        },
        "signature_version": "v1",
        "source": "https://github.com/crate/crate/commit/4e857d675683095945dd524d6ba03e692c70ecd6",
        "id": "CVE-2024-24565-4f8b74b2",
        "target": {
            "file": "server/src/test/java/io/crate/execution/engine/collect/files/FileReadingCollectorTest.java"
        }
    },
    {
        "signature_type": "Line",
        "deprecated": false,
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "85843753786877435194830668744511519950",
                "55818740283312133177637687939725200237",
                "242185975191798510168409193506776780496",
                "153713146843787868633138573480338022289",
                "179804489785161641689537124543649570162",
                "27926089142533857995397161124922794642",
                "227589597358446364027184145201459629302",
                "147724311950884598195777110181107971738",
                "267253316243687710238918199993699112330",
                "116675412723785258497379123786168510973",
                "76338990950032295777464119984949723032",
                "210816358823872581752627292159396412499",
                "117014046336710198522614876737255265723"
            ]
        },
        "signature_version": "v1",
        "source": "https://github.com/crate/crate/commit/4e857d675683095945dd524d6ba03e692c70ecd6",
        "id": "CVE-2024-24565-59c59c08",
        "target": {
            "file": "server/src/test/java/io/crate/integrationtests/CopyIntegrationTest.java"
        }
    },
    {
        "signature_type": "Line",
        "deprecated": false,
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "158591089354918472498013182694168455973",
                "158533304618116831211859779652179339031",
                "53340190274853161502765653049097024756",
                "27627964893603075053697708281570791505"
            ]
        },
        "signature_version": "v1",
        "source": "https://github.com/crate/crate/commit/3f27c19b9eb0b67d69f7ba704d3d384074986283",
        "id": "CVE-2024-24565-6b2ac7d4",
        "target": {
            "file": "server/src/main/java/org/elasticsearch/Version.java"
        }
    },
    {
        "signature_type": "Line",
        "deprecated": false,
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "242414013754950238388910550040515661971",
                "107856081388392021848558413757183394159",
                "331470277276726782152761211070002882314",
                "268416525470678081158683516048587674917"
            ]
        },
        "signature_version": "v1",
        "source": "https://github.com/crate/crate/commit/4e857d675683095945dd524d6ba03e692c70ecd6",
        "id": "CVE-2024-24565-76138e8c",
        "target": {
            "file": "plugins/cr8-copy-s3/src/test/java/io/crate/copy/s3/S3FileReadingCollectorTest.java"
        }
    },
    {
        "signature_type": "Line",
        "deprecated": false,
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "235968591446218974721304915035976204803",
                "215286264821763796144681002024806951100",
                "100639235571463518329891955450129085569",
                "98113162866041005545264563923217572457",
                "192086250632311920145310202095300464021",
                "45054811884184483472064747049352725026",
                "263176066025849640412423276674561869596",
                "123201654641119129367717796551509957400",
                "280906636195504681116634813389162387143",
                "339056629526742382037206350433853696225",
                "104992135985279180301067343580247774013",
                "140394716095046092220475580234011346333",
                "47024787017691719382889550790152591355",
                "164606416347601804052330824627430002670",
                "161511231020701911935934203137022910027",
                "101724990860404015923853004649553982355",
                "162582152025699774700401273858326719861",
                "300121080199217236341220029789733015701",
                "287446789591828436140210905496284164868",
                "36809901601537979182858328592234839995",
                "318741236213678008844048733169581634474",
                "95099193183731007593473061418410016903",
                "69112214954729111816325266289911363416",
                "181066873732007741627071198796583614027",
                "187708381550728570425883354514070472190",
                "14513129438954306959409581385051191194",
                "239398087064719094151810836805725195112"
            ]
        },
        "signature_version": "v1",
        "source": "https://github.com/crate/crate/commit/4e857d675683095945dd524d6ba03e692c70ecd6",
        "id": "CVE-2024-24565-762ab278",
        "target": {
            "file": "server/src/main/java/io/crate/execution/engine/collect/sources/FileCollectSource.java"
        }
    },
    {
        "signature_type": "Function",
        "deprecated": false,
        "digest": {
            "length": 1335.0,
            "function_hash": "52662607219395967650306768572080116085"
        },
        "signature_version": "v1",
        "source": "https://github.com/crate/crate/commit/4e857d675683095945dd524d6ba03e692c70ecd6",
        "id": "CVE-2024-24565-8755904f",
        "target": {
            "function": "testFileUriCollect",
            "file": "server/src/test/java/io/crate/execution/engine/collect/MapSideDataCollectOperationTest.java"
        }
    },
    {
        "signature_type": "Function",
        "deprecated": false,
        "digest": {
            "length": 1263.0,
            "function_hash": "312748328784151863168848527099296750112"
        },
        "signature_version": "v1",
        "source": "https://github.com/crate/crate/commit/4e857d675683095945dd524d6ba03e692c70ecd6",
        "id": "CVE-2024-24565-8a500adb",
        "target": {
            "function": "createBatchIterator",
            "file": "plugins/cr8-copy-s3/src/test/java/io/crate/copy/s3/S3FileReadingCollectorTest.java"
        }
    },
    {
        "signature_type": "Function",
        "deprecated": false,
        "digest": {
            "length": 1227.0,
            "function_hash": "105485602132483823573063128332201549208"
        },
        "signature_version": "v1",
        "source": "https://github.com/crate/crate/commit/4e857d675683095945dd524d6ba03e692c70ecd6",
        "id": "CVE-2024-24565-a2718c68",
        "target": {
            "function": "test_file_collect_source_returns_iterator_that_can_skip_lines",
            "file": "server/src/test/java/io/crate/execution/engine/collect/sources/FileCollectSourceTest.java"
        }
    },
    {
        "signature_type": "Line",
        "deprecated": false,
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "119919176908948717345113349317134901541",
                "26729152545588043802963990379790197350",
                "169025598007847140940506251077495940808",
                "9592288233787848493687791232690117842"
            ]
        },
        "signature_version": "v1",
        "source": "https://github.com/crate/crate/commit/4e857d675683095945dd524d6ba03e692c70ecd6",
        "id": "CVE-2024-24565-b039da3d",
        "target": {
            "file": "server/src/main/java/org/elasticsearch/ElasticsearchException.java"
        }
    },
    {
        "signature_type": "Line",
        "deprecated": false,
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "273697635909330489939438919369267573734",
                "57794465229366444597856431762108104456",
                "24213961106397963819564520094010832920",
                "253973813554817764474357082993629907184",
                "160765925439511450897081634599784721829",
                "114979648372529808611364304839794938601",
                "328026036699825846016979234018353675097",
                "37836009562310418655642356283407774042",
                "150950210913478097203820541935747960639",
                "100979717752675423388649523333851672431",
                "108774191585296767666855266320190871279",
                "313116509591660891773358367577483847222",
                "296454553910264711396352853494551045792",
                "269829530125993360284719692282562843349",
                "28101301288502984813586523698835196518",
                "34680954534116763779162694144559845088",
                "38264045606592378527061771719138265160",
                "56273009495675192758983626661555270683",
                "71709338256383202524690822091827035390",
                "327853185224135033545557776740962502810"
            ]
        },
        "signature_version": "v1",
        "source": "https://github.com/crate/crate/commit/4e857d675683095945dd524d6ba03e692c70ecd6",
        "id": "CVE-2024-24565-c5b19350",
        "target": {
            "file": "server/src/test/java/io/crate/execution/engine/collect/files/FileReadingIteratorTest.java"
        }
    },
    {
        "signature_type": "Function",
        "deprecated": false,
        "digest": {
            "length": 291.0,
            "function_hash": "289887131594403938220216475492339288930"
        },
        "signature_version": "v1",
        "source": "https://github.com/crate/crate/commit/4e857d675683095945dd524d6ba03e692c70ecd6",
        "id": "CVE-2024-24565-cdd05eeb",
        "target": {
            "function": "toFileInput",
            "file": "server/src/main/java/io/crate/execution/engine/collect/files/FileReadingIterator.java"
        }
    },
    {
        "signature_type": "Line",
        "deprecated": false,
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "140219674318479208660441538628858463633",
                "97769745626212878863080809029570468366",
                "280420905659162602144666336935330773687",
                "193335546464137732843807061750689114580",
                "237266381299993066564212914169214055611",
                "143433255583072576335916228782850307295",
                "122607479218162129677150989549149533391",
                "247676872703886960239398736093062791907"
            ]
        },
        "signature_version": "v1",
        "source": "https://github.com/crate/crate/commit/4e857d675683095945dd524d6ba03e692c70ecd6",
        "id": "CVE-2024-24565-d2236d65",
        "target": {
            "file": "server/src/test/java/io/crate/execution/engine/collect/MapSideDataCollectOperationTest.java"
        }
    },
    {
        "signature_type": "Function",
        "deprecated": false,
        "digest": {
            "length": 1946.0,
            "function_hash": "267028590168858684811614084479504087407"
        },
        "signature_version": "v1",
        "source": "https://github.com/crate/crate/commit/4e857d675683095945dd524d6ba03e692c70ecd6",
        "id": "CVE-2024-24565-e5d62259",
        "target": {
            "function": "test_retry_from_one_uri_does_not_affect_reading_next_uri",
            "file": "server/src/test/java/io/crate/execution/engine/collect/files/FileReadingIteratorTest.java"
        }
    },
    {
        "signature_type": "Function",
        "deprecated": false,
        "digest": {
            "length": 209.0,
            "function_hash": "139022454009219512855184743653143682162"
        },
        "signature_version": "v1",
        "source": "https://github.com/crate/crate/commit/4e857d675683095945dd524d6ba03e692c70ecd6",
        "id": "CVE-2024-24565-e9d4b55f",
        "target": {
            "function": "FileCollectSource",
            "file": "server/src/main/java/io/crate/execution/engine/collect/sources/FileCollectSource.java"
        }
    },
    {
        "signature_type": "Line",
        "deprecated": false,
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "219671659827715883228615834391158869922",
                "72343215048755626823765879814779398288",
                "165950037133280332235022297048780332654",
                "306704500463215945618028591687149431140",
                "312284236927502007544635419975510248070",
                "145317842870686624726424626370219254403",
                "301001903310417367047962093135043361420",
                "167259883206340827813640952156060177251",
                "195334785920275883610039777878197540089"
            ]
        },
        "signature_version": "v1",
        "source": "https://github.com/crate/crate/commit/4e857d675683095945dd524d6ba03e692c70ecd6",
        "id": "CVE-2024-24565-f032b6ff",
        "target": {
            "file": "server/src/main/java/io/crate/execution/engine/collect/files/FileReadingIterator.java"
        }
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-24565.json"