Davinci is a DVsaaS (Data Visualization as a Service) Platform
4.92k
stars
1.82k
forks
source link
DataSource Mysql JDBC Connection has two vulnerabilities : arbitrary file read and Server-side request forgery(SSRF) #2326
Open
Bertram2000 opened 1 year ago
use a malicious mysql server:
login and then Mysql JDBC Connection is set as a malicious server
Click Test Connection two vulnerabilities : 1.arbitrary file read:
success!
2.Server-side request forgery(SSRF) :
Visit Baidu success!
Repair suggestion: Set these properties to false:allowLoadLocalInfile、allowUrlInLocalInfile