CVE-2024-0006
DB User Password Leak in Application Log
Severity Score
5.4
*CVSS v4
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
Track*
*SSVC
Descriptions
Information exposure in the logging system in Yugabyte Platform allows local attackers with access to application logs to obtain database user credentials in log files, potentially leading to unauthorized database access.
La exposición de información en el sistema de registro de Yugabyte Platform permite a atacantes locales con acceso a los registros de aplicaciones obtener credenciales de usuario de la base de datos en archivos de registro, lo que podría conducir a un acceso no autorizado a la base de datos.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
System
Vulnerable | Subsequent
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:Track*
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2023-11-07 CVE Reserved
- 2024-07-19 CVE Published
- 2024-07-20 EPSS Updated
- 2024-08-01 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-532: Insertion of Sensitive Information into Log File
CAPEC
- CAPEC-560: Use of Known Domain Credentials
References (3)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
YugabyteDB Search vendor "YugabyteDB" | Yuga Search vendor "YugabyteDB" for product "Yuga" | >= 2.18.0.0 < 2.18.9.0 Search vendor "YugabyteDB" for product "Yuga" and version " >= 2.18.0.0 < 2.18.9.0" | en |
Affected
| ||||||
YugabyteDB Search vendor "YugabyteDB" | Yuga Search vendor "YugabyteDB" for product "Yuga" | >= 2.20.0.0 < 2.20.2.3 Search vendor "YugabyteDB" for product "Yuga" and version " >= 2.20.0.0 < 2.20.2.3" | en |
Affected
|