Junglewise Threat Intelligence

CVE-2024-56325: Apache Pinot authentication bypass via path traversal

CVE-2024-56325 · Severity: critical · CVSS 9.8 · Published 2025-04-01

Vendors: Maven, Apache.

Executive brief

Apache Pinot is a real-time distributed data store used for analytics and search across large datasets. This vulnerability allows attackers on the network to bypass authentication entirely and create administrator accounts without credentials, gaining complete control over the Pinot cluster. An attacker could then access, modify, or delete sensitive data, disrupt service availability, or use the cluster for further attacks on internal systems.

Technical details

This is an authentication bypass vulnerability (CWE-288: Authentication Bypass Using an Alternate Path or Channel) affecting the user management API endpoint. The root cause is a flawed path validation check that skips authentication if the request path does not contain a forward slash (/) but does contain a dot (.). An unauthenticated attacker can exploit this via a network request to create an admin user by crafting a malicious POST to an endpoint like `/users; .` (note the semicolon and dot), which bypasses the authentication filter while still reaching the user creation handler. The attack requires no prior credentials, user interaction, or privilege level. Successful exploitation enables complete administrative control over Pinot, including data access, modification, deletion, and system configuration. The vulnerability has been patched in version 1.3.0; affected versions are 0.8.0 through 1.2.x of pinot-broker, pinot-common, and pinot-controller.

Affected products

  • Apache Pinot Broker 0.8.0 to 1.2.x
  • Apache Pinot Common 0.8.0 to 1.2.x
  • Apache Pinot Controller 0.8.0 to 1.2.x

Timeline

  • 2025-04-01: disclosed: Published by GitHub Advisory Database and NVD
  • 2025-04-01: patched: Fix available in version 1.3.0

References

Related threats