TiDB server (importer CLI tool) prior to version 6.4.0 & 6.1.3 is vulnerable to data source name injection. The database name for generating and inserting data into a database does not properly sanitize user input which can lead to arbitrary file reads."
{
"nvd_published_at": "2022-11-04T12:15:00Z",
"github_reviewed": true,
"cwe_ids": [
"CWE-134"
],
"severity": "CRITICAL",
"github_reviewed_at": "2022-11-04T20:48:44Z"
}