Dremio Corporation
Dremio Corporation develops a data-analytics and query-optimization platform that has surfaced vulnerabilities centered on path-traversal weaknesses in its core product. The observed exposure reflects input-validation handling in a system designed to access and federate diverse data sources, where proper pathname restrictions are essential to preventing unintended directory access. Current severity, exploitation activity, and exposure details are shown alongside this summary.
Trends Over Time
The number and severity of CVEs published that impact products developed by Dremio Corporation over time
Self-Reporting Analysis
Of all the CVEs published by Dremio Corporation as a CNA, 0.0% affect products that Dremio Corporation develops as a vendor.
Of all the CVEs published that affect products developed by Dremio Corporation, 0.0% are self-published by Dremio Corporation as a CNA.
Products(1 total)
Top CVEs
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-23768HIGH Dremio before 24.3.1 allows path traversal. An authenticated user who has no privileges on certain folders (and the files and datasets in these folders) can access these folders, f | Jan 22, 2024 | 8.8 | 24 | NO | NO |
CVE Severity & Scoring
Exploit Exposure
Signals from CVEs in this vendor scope (1 CVEs).
Social Chatter
An overview of all social media posts that mention a CVE ID that affects a product developed by Dremio Corporation.
Media Mentions
Media articles that mention a CVE ID that affects a product developed by Dremio Corporation — matched by CVE ID, not by vendor name.