Executive brief
CrateDB, a distributed SQL database, contains a security flaw in how it handles large file storage (blobs) via its web interface. While the database correctly restricts access when using standard database commands, it fails to check permissions when files are accessed directly via web links. This allows any registered user to read or delete files they shouldn't have access to, provided they know the file's unique identifier, and allows them to upload new files without restriction.
Technical details
The vulnerability exists in the `io.crate.protocols.http.HttpBlobHandler` component of CrateDB. While the SQL interface correctly utilizes `AccessControl` to enforce privileges, the HTTP API (`/_blobs/{table}/{digest}`) authenticates requests but fails to verify if the authenticated user has the necessary DQL (for GET/HEAD) or DML (for PUT/DELETE) permissions on the target blob table. An attacker with valid credentials can read or delete any blob if they know its SHA-1 digest, and can upload new blobs to any table regardless of assigned privileges. The issue is resolved in versions 6.2.8 and 6.3.2 by integrating `AccessControl` checks into the HTTP request dispatcher.
Affected products
- Crate.io CrateDB < 6.2.8, >= 6.3.0, < 6.3.2
Timeline
- 2026-05-27: disclosed: Initial advisory publication
- 2026-07-01: advisory: Advisory updated with patch information