CVE-2024-11165

MEDIUM

YugabyteDB Anywhere <2.20.7.0-<2.23.0.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

An information disclosure vulnerability exists in the backup configuration process where the SAS token is not masked in the configuration response. This oversight results in sensitive information leakage within the yb_backup log files, exposing the SAS token in plaintext. The leakage occurs during the backup procedure, leading to potential unauthorized access to resources associated with the SAS token. This issue affects YugabyteDB Anywhere: from 2.20.0.0 before 2.20.7.0, from 2.23.0.0 before 2.23.1.0, from 2024.1.0.0 before 2024.1.3.0.

Scores

CVSS v4 5.7
EPSS 0.0014
EPSS Percentile 3.4%
CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:L/VI:H/VA:L/SC:L/SI:L/SA:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-532
Status published
Products (3)
YugabyteDB/YugabyteDB Anywhere 2.20.0.0 - 2.20.7.0
YugabyteDB/YugabyteDB Anywhere 2.23.0.0 - 2.23.1.0
YugabyteDB/YugabyteDB Anywhere 2024.1.0.0 - 2024.1.3.0
Published Nov 13, 2024
Tracked Since Feb 18, 2026