Collected research
Databricks JDBC Attack via JAAS
The Databricks JDBC driver accepts a JAAS config property pointing at a remote URL, so a victim using an attacker-supplied connection string fetches a config naming a JNDI login module with an attacker LDAP provider URL, turning the connection into JNDI injection and remote code execution in the driver's process.
Record
- Researcher
- pyn3rd
- Published by
- blog.pyn3rd.com
- Date
- Topic
- Other
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of pyn3rd, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .