CVE-2024-0006

MEDIUM

Yugabyte Platform - Info Disclosure

Title source: llm
STIX 2.1

Description

Information exposure in the logging system in Yugabyte Platform allows local attackers with access to application logs to obtain database user credentials in log files, potentially leading to unauthorized database access.

Scores

CVSS v4 5.4
EPSS 0.0007
EPSS Percentile 22.0%
CVSS:4.0/AV:A/AC:H/AT:N/PR:H/UI:A/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-532
Status published
Products (3)
YugabyteDB/YugabyteDB Anywhere 2.18.0.0 - 2.18.9.0
YugabyteDB/YugabyteDB Anywhere 2.20.0.0 - 2.20.2.3
YugabyteDB/YugabyteDB Anywhere 2024.0.0.0 - 2024.1.1.0
Published Jul 19, 2024
Tracked Since Feb 18, 2026