CyberRota Analysis
AI-GeneratedA vulnerability in the Flint extension query handler of the OpenSearch SQL plugin for Apache allows remote authenticated users with async query access to bypass SQL query validation, enabling them to execute arbitrary code on Apache Spark workers via crafted SQL queries. This poses a high risk, as it could lead to unauthorized access and control over the affected systems. Organizations using Apache with the OpenSearch SQL plugin should prioritize patching this vulnerability to mitigate potential exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A SQL query validation bypass in the Flint extension query handler in the OpenSearch SQL plugin allows a remote authenticated actor with async query access to execute arbitrary code on Apache Spark workers by sending a crafted SQL query to the direct query endpoint.