Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-64640

Gravedad CVSS v4.0:
MEDIA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
06/08/2026
Última modificación:
06/08/2026

Descripción

*** Pendiente de traducción *** Apache Polaris did not consistently validate storage locations supplied during table and view registration.<br /> <br /> An authenticated principal with permission to register a table or view could, depending on the affected release and registration path, cause Polaris to use the catalog&amp;#39;s storage credentials to read a caller-selected Iceberg metadata file before verifying that the file was within the catalog&amp;#39;s allowed storage locations.<br /> <br /> If the catalog&amp;#39;s underlying credentials could read an object outside that boundary, this could disclose limited information from the object.<br /> <br /> <br /> Polaris could also accept registration metadata located within an allowed location that contained references to storage locations outside the allowed boundary.<br /> <br /> This second condition did not itself cause Polaris to read the referenced external locations during registration.<br /> <br /> <br /> The demonstrated impact is limited to confidentiality.<br /> <br /> No unauthorized data modification or availability impact has been demonstrated.<br /> <br /> <br /> The server-side read requires a deployment using S3 credential vending and an object outside the allowed locations that the catalog&amp;#39;s underlying storage credentials can read.<br /> <br /> Exploitation requires an authenticated principal with table- or view-registration privileges.

Productos y versiones vulnerables

CPE Desde Hasta
cpe:2.3:a:apache:polaris:*:*:*:*:*:*:*:* 1.6.0 (incluyendo)


Referencias a soluciones, herramientas e información