Home » Database

AVID-2026-R1501

Description

Vulnerability CVE-2024-38302

Details

Dell Data Lakehouse, version(s) 1.0.0.0, contain(s) a Missing Encryption of Sensitive Data vulnerability in the DDAE (Starburst). A low privileged attacker with adjacent network access could potentially exploit this vulnerability, leading to Information disclosure.

Reason for inclusion in AVID: CVE-2024-38302 describes a missing encryption vulnerability in Dell Data Lakehouse (DDAE/Starburst) that allows information disclosure with adjacent network access. Dell Data Lakehouse is software used in data pipelines for AI/ML workflows (data storage/processing for training, serving, etc.), making it AI-related and part of the general-purpose AI systems supply chain. The issue is a security vulnerability (data leakage) with evidence in the CVE/NVD references. Therefore it should be kept for AVID curation as a software supply chain vulnerability affecting AI systems.

References

Affected or Relevant Artifacts

  • Developer: Dell
  • Deployer: Dell
  • Artifact Details:
TypeName
SystemDell Data Lakehouse

Impact

AVID Taxonomy Categorization

  • Risk domains: Security
  • SEP subcategories: S0100: Software Vulnerability
  • Lifecycle stages: L06: Deployment

CVSS

Version3.1
Vector StringCVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Base Score6.8
Base Severity🟠 Medium
Attack VectorADJACENT_NETWORK
Attack Complexity🟢 Low
Privileges Required🟢 Low
User InteractionNONE
ScopeCHANGED
Confidentiality Impact🔴 High
Integrity ImpactNONE
Availability ImpactNONE

CWE

IDDescription
CWE-311CWE-311: Missing Encryption of Sensitive Data

Other information

  • Report Type: Advisory
  • Credits:
  • Date Reported: 2024-07-18
  • Version: 0.3.3
  • AVID Entry