CVE-2024-23768: Dremio

High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.

Dremio before 24.3.1 allows path traversal. An authenticated user who has no privileges on certain folders (and the files and datasets in these folders) can access these folders, files, and datasets. To be successful, the user must have access to the source and at least one folder in the source. Affected versions are: 24.0.0 through 24.3.0, 23.0.0 through 23.2.3, and 22.0.0 through 22.2.2. Fixed versions are: 24.3.1 and later, 23.2.4 and later, and 22.2.3 and later.

Affected products

  • Dremio Dremio: from 22.0.0, before 22.2.3 (fixed in 22.2.3); from 23.0.0, before 23.2.4 (fixed in 23.2.4); from 24.0.0, before 24.3.1 (fixed in 24.3.1)

Published 2024-01-22. Last modified 2026-06-17.