« Volver al listado

Apache

Apache Polaris: vulnerabilidades y CVE

Apache Polaris tiene 6 vulnerabilidades publicadas, 6 de ellas en los últimos 12 meses. 4 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE6
Últimos 12 meses6
Críticas4
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-97395Alta (8.1)0.28%—29 sept 2026
Apache Polaris allows an authenticated principal with permission to create or update Iceberg table properties to set FileIO client settings such as s3.endpoint in table metadata. In versions < 1.8.0, when Polaris…
CVE-2026-64640Media (5.3)0.49%—6 ago 2026
Apache Polaris did not consistently validate storage locations supplied during table and view registration. An authenticated principal with permission to register a table or view could, depending on the affected release…
CVE-2026-42812Crítica (9.4)0.59%—4 may 2026
In Apache Iceberg, the table's metadata files are control files: they tell readers which data files belong to the table and which table version to read. `write.metadata.path` is an optional table property that tells…
CVE-2026-42811Crítica (9.4)0.72%—4 may 2026
In plain terms, Apache Polaris is supposed to issue short-lived GCS credentials that only work for one table's files, but a crafted namespace or table name can cause those credentials to work across the configured…
CVE-2026-42810Crítica (9.4)0.69%—4 may 2026
Apache Polaris accepts literal `*` characters in namespace and table names. When it later builds temporary S3 access policies for delegated table access, those same characters appear to be reused unescaped in S3 IAM…
CVE-2026-42809Crítica (9.4)0.58%—4 may 2026
Apache Polaris can issue broad temporary ("vended") storage credentials during staged table creation before the effective table location has been validated or durably reserved. Those temporary credentials are meant to…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1210 Exploitation of Remote Services5
  2. T1005 Data from Local System1
  3. T1078 Valid Accounts1
  4. T1078.004 Cloud Accounts1
  5. T1552.007 Container API1
  6. T1565.001 Stored Data Manipulation1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

📰 Noticias relacionadas

Otros productos de Apache