WhisperX tag archive

#mariadb

This page collects WhisperX intelligence signals tagged #mariadb. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (3)

The Lab · 2026-04-29 22:54:12 · GitHub Issues

1. Apache Superset Reverts MariaDB Security Patch, Reintroducing Arbitrary File Read Vulnerability CVE-2024-34693

A critical security fix addressing CVE-2024-34693 has been removed from Apache Superset, restoring a vulnerability that allows authenticated users to read arbitrary files from MariaDB servers. The revert strips away local_infile connection parameter restrictions from MariaDBEngineSpec, enabling LOAD DATA LOCAL INFILE t...

The Lab · 2026-04-30 17:54:09 · GitHub Issues

2. Apache Superset Flaw Enables Authenticated Attackers to Read Arbitrary Server Files via MariaDB

A critical input validation vulnerability in Apache Superset exposes affected installations to arbitrary file read attacks by authenticated users through specially crafted MariaDB connections. The flaw leverages the LOCAL_INFILE capability—a database feature disabled by default on MariaDB servers but potentially exploi...

The Lab · 2026-04-30 17:54:14 · GitHub Issues

3. Apache Superset Vulnerability Allows Authenticated Attackers to Read Server Files via MariaDB Connection

A critical input validation flaw in Apache Superset enables authenticated attackers to leverage MariaDB's local_infile functionality to read arbitrary files from the web server. The vulnerability, tracked as CVE-related to improper input validation, permits an attacker who can create a MariaDB database connection to ex...