TiDB server (importer CLI tool) prior to version 6.4.0 & 6.1.3 is vulnerable to data source name injection. The database name for generating and inserting data into a database does not properly sanitize user input which can lead to arbitrary file reads."
{ "nvd_published_at": "2022-11-04T12:15:00Z", "github_reviewed_at": "2022-11-04T20:48:44Z", "severity": "CRITICAL", "github_reviewed": true, "cwe_ids": [ "CWE-134" ] }