CVE-2024-11165
MEDIUMYugabyteDB Anywhere <2.20.7.0-<2.23.0.0 - Info Disclosure
Title source: llmDescription
An information disclosure vulnerability exists in the backup configuration process where the SAS token is not masked in the configuration response. This oversight results in sensitive information leakage within the yb_backup log files, exposing the SAS token in plaintext. The leakage occurs during the backup procedure, leading to potential unauthorized access to resources associated with the SAS token. This issue affects YugabyteDB Anywhere: from 2.20.0.0 before 2.20.7.0, from 2.23.0.0 before 2.23.1.0, from 2024.1.0.0 before 2024.1.3.0.
References (1)
Core 1
Scores
CVSS v4
5.7
EPSS
0.0014
EPSS Percentile
3.4%
CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:L/VI:H/VA:L/SC:L/SI:L/SA:L
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-532
Status
published
Products (3)
YugabyteDB/YugabyteDB Anywhere
2.20.0.0 - 2.20.7.0
YugabyteDB/YugabyteDB Anywhere
2.23.0.0 - 2.23.1.0
YugabyteDB/YugabyteDB Anywhere
2024.1.0.0 - 2024.1.3.0
Published
Nov 13, 2024
Tracked Since
Feb 18, 2026