Search

Find a vulnerability

Search criteria

    3 vulnerabilities found for yugabytedb by yugabyte

    CVE-2024-41435 (GCVE-0-2024-41435)

    Vulnerability from cvelistv5 – Published: 2024-09-03 00:00 – Updated: 2024-09-03 20:15
    VLAI
    Summary
    YugabyteDB v2.21.1.0 was discovered to contain a buffer overflow via the "insert into" parameter.
    SSVC
    Exploitation: poc Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-09-03 20:13 UTC
    CWE
    • n/a
    • CWE-120 - Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
    Impacted products
    Vendor Product Version
    yugabyte yugabytedb Affected: 2.21.1.0
        cpe:2.3:a:yugabyte:yugabytedb:2.21.1.0:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:yugabyte:yugabytedb:2.21.1.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "yugabytedb",
                "vendor": "yugabyte",
                "versions": [
                  {
                    "status": "affected",
                    "version": "2.21.1.0"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "HIGH",
                  "baseScore": 7.5,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "NONE",
                  "integrityImpact": "NONE",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-41435",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-09-03T20:13:37.543021Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-120",
                    "description": "CWE-120 Buffer Copy without Checking Size of Input (\u0027Classic Buffer Overflow\u0027)",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-09-03T20:15:08.289Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "YugabyteDB v2.21.1.0 was discovered to contain a buffer overflow via the \"insert into\" parameter."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-09-03T19:10:16.203Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "url": "https://github.com/yugabyte/yugabyte-db/issues/22967"
            },
            {
              "url": "https://gist.github.com/ycybfhb/1427881e7db911786837d32b0669e06b"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2024-41435",
        "datePublished": "2024-09-03T00:00:00.000Z",
        "dateReserved": "2024-07-18T00:00:00.000Z",
        "dateUpdated": "2024-09-03T20:15:08.289Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-6895 (GCVE-0-2024-6895)

    Vulnerability from cvelistv5 – Published: 2024-07-19 14:47 – Updated: 2024-08-13 20:45
    VLAI
    Title
    Insecure Account Profile Management
    Summary
    Insufficient authentication in user account management in Yugabyte Platform allows local network attackers with a compromised user session to change critical security information without re-authentication. An attacker with user session and access to application can modify settings such as password and email without being prompted for the current password, enabling account takeover.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-07-19 16:38 UTC
    CWE
    • CWE-306 - Missing Authentication for Critical Function
    References
    Impacted products
    Vendor Product Version
    YugabyteDB YugabyteDB Anywhere Affected: 2.14.0.0 , ≤ 2.14.17.0 (git)
    Affected: 2.16.0.0 , ≤ 2.16.9.0 (git)
    Affected: 2.18.0.0 , ≤ 2.18.8.1 (git)
    Affected: 2.20.0.0 , < 2.20.5.0 (git)
    Create a notification for this product.
    yugabyte yugabytedb Affected: 2.14.0.0 , ≤ 2.14.17.0 (git)
    Affected: 2.16.0.0 , ≤ 2.16.9.0 (git)
    Affected: 2.18.0.0 , ≤ 2.18.8.1 (git)
    Affected: 2.20.0.0 , < 2.20.5.0 (git)
        cpe:2.3:a:yugabyte:yugabytedb:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2024-07-18 21:24
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:yugabyte:yugabytedb:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "yugabytedb",
                "vendor": "yugabyte",
                "versions": [
                  {
                    "lessThanOrEqual": "2.14.17.0",
                    "status": "affected",
                    "version": "2.14.0.0",
                    "versionType": "git"
                  },
                  {
                    "lessThanOrEqual": "2.16.9.0",
                    "status": "affected",
                    "version": "2.16.0.0",
                    "versionType": "git"
                  },
                  {
                    "lessThanOrEqual": "2.18.8.1",
                    "status": "affected",
                    "version": "2.18.0.0",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "2.20.5.0",
                    "status": "affected",
                    "version": "2.20.0.0",
                    "versionType": "git"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-6895",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-07-19T16:38:09.286512Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-08-13T20:45:30.139Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-01T21:45:38.424Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "patch",
                  "x_transferred"
                ],
                "url": "https://github.com/yugabyte/yugabyte-db/commit/9687371d8777f876285b737a9d01995bc46bafa5"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "platforms": [
                "Linux",
                "Docker",
                "Kubernetes"
              ],
              "product": "YugabyteDB Anywhere",
              "vendor": "YugabyteDB",
              "versions": [
                {
                  "lessThanOrEqual": "2.14.17.0",
                  "status": "affected",
                  "version": "2.14.0.0",
                  "versionType": "git"
                },
                {
                  "lessThanOrEqual": "2.16.9.0",
                  "status": "affected",
                  "version": "2.16.0.0",
                  "versionType": "git"
                },
                {
                  "lessThanOrEqual": "2.18.8.1",
                  "status": "affected",
                  "version": "2.18.0.0",
                  "versionType": "git"
                },
                {
                  "lessThan": "2.20.5.0",
                  "status": "affected",
                  "version": "2.20.0.0",
                  "versionType": "git"
                }
              ]
            }
          ],
          "datePublic": "2024-07-18T21:24:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Insufficient authentication in user account management in Yugabyte Platform allows local network attackers with a compromised user session to change critical security information without re-authentication. An attacker with user session and access to application can modify settings such as password and email without being prompted for the current password, enabling account takeover."
                }
              ],
              "value": "Insufficient authentication in user account management in Yugabyte Platform allows local network attackers with a compromised user session to change critical security information without re-authentication. An attacker with user session and access to application can modify settings such as password and email without being prompted for the current password, enabling account takeover."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-21",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-21 Exploitation of Trusted Identifiers"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "HIGH",
                "attackRequirements": "NONE",
                "attackVector": "ADJACENT",
                "baseScore": 6.1,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "HIGH",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "HIGH",
                "subConfidentialityImpact": "HIGH",
                "subIntegrityImpact": "HIGH",
                "userInteraction": "PASSIVE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:A/AC:H/AT:N/PR:H/UI:P/VC:H/VI:L/VA:L/SC:H/SI:H/SA:H",
                "version": "4.0",
                "vulnAvailabilityImpact": "LOW",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "LOW",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-306",
                  "description": "CWE-306 Missing Authentication for Critical Function",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-07-19T14:47:50.432Z",
            "orgId": "d4ae51d3-4db5-465e-bc8a-eb6768324078",
            "shortName": "Yugabyte"
          },
          "references": [
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/yugabyte/yugabyte-db/commit/9687371d8777f876285b737a9d01995bc46bafa5"
            }
          ],
          "source": {
            "defect": [
              "PLAT-10472"
            ],
            "discovery": "UNKNOWN"
          },
          "title": "Insecure Account Profile Management",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "d4ae51d3-4db5-465e-bc8a-eb6768324078",
        "assignerShortName": "Yugabyte",
        "cveId": "CVE-2024-6895",
        "datePublished": "2024-07-19T14:47:50.432Z",
        "dateReserved": "2024-07-18T20:20:00.305Z",
        "dateUpdated": "2024-08-13T20:45:30.139Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-0006 (GCVE-0-2024-0006)

    Vulnerability from cvelistv5 – Published: 2024-07-19 14:26 – Updated: 2024-08-01 17:41
    VLAI
    Title
    DB User Password Leak in Application Log
    Summary
    Information exposure in the logging system in Yugabyte Platform allows local attackers with access to application logs to obtain database user credentials in log files, potentially leading to unauthorized database access.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-07-23 14:31 UTC
    CWE
    • CWE-532 - Insertion of Sensitive Information into Log File
    Impacted products
    Vendor Product Version
    YugabyteDB YugabyteDB Anywhere Affected: 2.18.0.0 , < 2.18.9.0 (git)
    Affected: 2.20.0.0 , < 2.20.2.3 (git)
    Affected: 2024.0.0.0 , < 2024.1.1.0 (git)
    Create a notification for this product.
    yugabyte yugabytedb Affected: 2.18.0.0 , < 2.18.9.0 (custom)
    Affected: 2.20.0.0 , < 2.20.2.3 (custom)
    Affected: 2024.0.0.0 , < 2024.1.1.0 (custom)
        cpe:2.3:a:yugabyte:yugabytedb:2.18.0.0:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2024-07-18 19:42
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:yugabyte:yugabytedb:2.18.0.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "yugabytedb",
                "vendor": "yugabyte",
                "versions": [
                  {
                    "lessThan": "2.18.9.0",
                    "status": "affected",
                    "version": "2.18.0.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "2.20.2.3",
                    "status": "affected",
                    "version": "2.20.0.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "2024.1.1.0",
                    "status": "affected",
                    "version": "2024.0.0.0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-0006",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-07-23T14:31:12.448030Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-07-23T14:32:54.285Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-01T17:41:15.316Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "patch",
                  "x_transferred"
                ],
                "url": "https://github.com/yugabyte/yugabyte-db/commit/439c6286f1971f9ac6bff2c7215b454c2025c593"
              },
              {
                "tags": [
                  "patch",
                  "x_transferred"
                ],
                "url": "https://github.com/yugabyte/yugabyte-db/commit/d96e6b629f34d065b47204daeeb44064e484c579"
              },
              {
                "tags": [
                  "patch",
                  "x_transferred"
                ],
                "url": "https://github.com/yugabyte/yugabyte-db/commit/5cc7f4e15d6ccccbf97c57946fd0aa630f88c9e2"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "platforms": [
                "Linux",
                "Docker",
                "Kubernetes"
              ],
              "product": "YugabyteDB Anywhere",
              "vendor": "YugabyteDB",
              "versions": [
                {
                  "lessThan": "2.18.9.0",
                  "status": "affected",
                  "version": "2.18.0.0",
                  "versionType": "git"
                },
                {
                  "lessThan": "2.20.2.3",
                  "status": "affected",
                  "version": "2.20.0.0",
                  "versionType": "git"
                },
                {
                  "lessThan": "2024.1.1.0",
                  "status": "affected",
                  "version": "2024.0.0.0",
                  "versionType": "git"
                }
              ]
            }
          ],
          "datePublic": "2024-07-18T19:42:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Information exposure in the logging system in Yugabyte Platform allows local attackers with access to application logs to obtain database user credentials in log files, potentially leading to unauthorized database access."
                }
              ],
              "value": "Information exposure in the logging system in Yugabyte Platform allows local attackers with access to application logs to obtain database user credentials in log files, potentially leading to unauthorized database access."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-560",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-560 Use of Known Domain Credentials"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "HIGH",
                "attackRequirements": "NONE",
                "attackVector": "ADJACENT",
                "baseScore": 5.4,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "HIGH",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "LOW",
                "subConfidentialityImpact": "LOW",
                "subIntegrityImpact": "LOW",
                "userInteraction": "ACTIVE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:A/AC:H/AT:N/PR:H/UI:A/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-532",
                  "description": "CWE-532 Insertion of Sensitive Information into Log File",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-07-19T14:26:14.160Z",
            "orgId": "d4ae51d3-4db5-465e-bc8a-eb6768324078",
            "shortName": "Yugabyte"
          },
          "references": [
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/yugabyte/yugabyte-db/commit/439c6286f1971f9ac6bff2c7215b454c2025c593"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/yugabyte/yugabyte-db/commit/d96e6b629f34d065b47204daeeb44064e484c579"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/yugabyte/yugabyte-db/commit/5cc7f4e15d6ccccbf97c57946fd0aa630f88c9e2"
            }
          ],
          "source": {
            "defect": [
              "PLAT-14286"
            ],
            "discovery": "UNKNOWN"
          },
          "title": "DB User Password Leak in Application Log",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "d4ae51d3-4db5-465e-bc8a-eb6768324078",
        "assignerShortName": "Yugabyte",
        "cveId": "CVE-2024-0006",
        "datePublished": "2024-07-19T14:26:14.160Z",
        "dateReserved": "2023-11-07T22:19:42.717Z",
        "dateUpdated": "2024-08-01T17:41:15.316Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }