Impact
StarRocks 4.0.13 and earlier expose unfiltered query history via the query_detail endpoint. An authenticated user with low privileges can retrieve complete SQL text, execution plans, and profiling data for every query run by other users, potentially revealing sensitive credentials. This information disclosure flaw (CWE‑200) compromises confidentiality and can lead to credential theft and further attacks.
Affected Systems
The affected product is StarRocks. Versions through 4.0.13 are vulnerable; any installation running these releases is at risk. The flaw exists in the Front End component, specifically the QueryDetailAction handler.
Risk and Exploitability
The CVSS score of 6.5 denotes a medium to high severity vulnerability. EPSS is not available, so the current probability of exploitation is unknown; however, the flaw is accessible to any authenticated user, which lowers the barrier to attack. The vulnerability is not listed in the CISA KEV catalog, indicating no public exploitation evidence yet, but the impact warrants prompt remediations.
OpenCVE Enrichment