Cratedb is a distributed SQL database platform with a limited but recognized vulnerability footprint centered on its core database product. The exposure reflects characteristic weaknesses in resource management, authentication mechanisms, and path-handling logic that recur across database and data-serving platforms. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cratedb over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-24565MEDIUM CrateDB is a distributed SQL database that makes it simple to store and analyze massive amounts of data in real-time. There is a COPY FROM function in the CrateDB database that is | Jan 30, 2024 | 6.5 | 26 | NO | YES |
CVE-2023-51982CRITICAL CrateDB 5.5.1 is contains an authentication bypass vulnerability in the Admin UI component. After configuring password authentication and_ Local_ In the case of an address, identit | Jan 30, 2024 | 9.8 | 26 | NO | NO |
CVE-2024-37309MEDIUM CrateDB is a distributed SQL database. A high-risk vulnerability has been identified in versions prior to 5.7.2 where the TLS endpoint (port 4200) permits client-initiated renegoti | Jun 13, 2024 | 5.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cratedb.
Media articles that mention a CVE ID that affects a product developed by Cratedb — matched by CVE ID, not by vendor name.