CVE-2024-0006

Information exposure in the logging system in Yugabyte Platform allows local attackers with access to application logs to obtain database user credentials in log files, potentially leading to unauthorized database access.
CVSS

No CVSS.

Configurations

No configuration.

History

21 Nov 2024, 08:45

Type Values Removed Values Added
References () https://github.com/yugabyte/yugabyte-db/commit/439c6286f1971f9ac6bff2c7215b454c2025c593 - () https://github.com/yugabyte/yugabyte-db/commit/439c6286f1971f9ac6bff2c7215b454c2025c593 -
References () https://github.com/yugabyte/yugabyte-db/commit/5cc7f4e15d6ccccbf97c57946fd0aa630f88c9e2 - () https://github.com/yugabyte/yugabyte-db/commit/5cc7f4e15d6ccccbf97c57946fd0aa630f88c9e2 -
References () https://github.com/yugabyte/yugabyte-db/commit/d96e6b629f34d065b47204daeeb44064e484c579 - () https://github.com/yugabyte/yugabyte-db/commit/d96e6b629f34d065b47204daeeb44064e484c579 -

22 Jul 2024, 13:00

Type Values Removed Values Added
Summary
  • (es) La exposición de información en el sistema de registro de Yugabyte Platform permite a atacantes locales con acceso a los registros de aplicaciones obtener credenciales de usuario de la base de datos en archivos de registro, lo que podría conducir a un acceso no autorizado a la base de datos.

19 Jul 2024, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-19 15:15

Updated : 2024-11-21 08:45


NVD link : CVE-2024-0006

Mitre link : CVE-2024-0006

CVE.ORG link : CVE-2024-0006


JSON object : View

Products Affected

No product.

CWE
CWE-532

Insertion of Sensitive Information into Log File