YugaByte, Inc. Vulnerabilities and Affected Products
Vulnerabilities associated with Yugabyte DB.
Products
Clear product- Yugabyte DB1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2022-37397HIGH | The software is vulnerable when using LDAP-based authentication in YCQL with Microsoft’s Active DirectoryAn issue was discovered in the YugabyteDB 2.6.1 when using LDAP-based authentication in YCQL with Microsoft’s Active Directory. When anonymous or unauthenticated LDAP binding is enabled, it allows bypass of authentication with an empty password. | CVSS8.3v3.1 | EPSS0.868% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |