GHSA-7fxj-fr3v-r9gj
CRITICALCVE-2022-3023TiDB server (importer CLI tool) prior to version 6.4.0 & 6.1.3 is vulnerable to data source name injection. The database name for generating and inserting data into a database does not properly sanitize user input which can lead to arbitrary file reads."
- Affected
- >= 6.2.0, <= 6.4.0-alpha1, <= 6.1.2
- Fixed in
- not stated
- Weakness
- CWE-134
- Published
- 2022-11-04
- Source
- github