CVE-2026-34214
בינונית 6.5
תיאור (מקור, אנגלית)
Trino is a distributed SQL query engine for big data analytics. From version 439 to before version 480, Iceberg connector REST catalog static credentials (access key) or vended credentials (temporary access key) are accessible to users that have write privilege on SQL level. This issue has been patched in version 480.
מדדים
- CVSS 3.1
-
6.5 (MEDIUM)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N - EPSS — סבירות ניצול
- 0% (אחוזון 000) נכון ל-26/7/2026
- CWE
- CWE-212, CWE-312
מוצרים מושפעים
trino: trino
קישורים
- https://github.com/trinodb/trino/security/advisories/GHSA-x27p-5f68-m644 Vendor Advisory
- https://github.com/trinodb/trino/releases/tag/480 Release Notes