Vulnerability index

Browse CVEs

8 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2024-41435 YugabyteDB v2.21.1.0 was discovered to contain a buffer overflow via the "insert into" parameter. Yugabytedb No fix yet Fix from $1,9502024-09-03 MEDIUM 6.1 CVE-2023-6002 YugabyteDB is vulnerable to cross site scripting (XSS) via log injection. Writing invalidated user input to log files can allow an unprivileged attac… Yugabytedb 2.14.14.0 / 2.16.8.0+ Fix from $1,6002023-11-08 HIGH 7.5 CVE-2023-6001 Prometheus metrics are available without authentication. These expose detailed and sensitive information about the YugabyteDB Anywhere environment. Yugabytedb 2.18.4.0+ Fix from $1,9502023-11-08 HIGH 7.5 CVE-2023-4640 The controller responsible for setting the logging level does not include any authorization checks to ensure the user is authenticated. This can be s… Yugabytedb after 2.17.3.0 Fix from $1,9502023-08-30 CRITICAL 9.8 CVE-2023-0745 The High Availability functionality of Yugabyte Anywhere can be abused to write arbitrary files through the backup upload endpoint by using path trav… Yugabytedb Managed after 2.13 Fix from $2,3002023-02-09 CRITICAL 9.8 CVE-2023-0575 External Control of Critical State Data, Improper Control of Generation of Code ('Code Injection') vulnerability in YugaByte, Inc. Yugabyte DB on Win… Yugabytedb 2.2.0.0+ Fix from $2,3002023-02-09 CRITICAL 9.8 CVE-2023-0574 Server-Side Request Forgery (SSRF), Improperly Controlled Modification of Dynamically-Determined Object Attributes, Improper Restriction of Excessive… Yugabytedb Managed after 2.13 Fix from $2,3002023-02-09 CRITICAL 9.8 CVE-2022-37397 An issue was discovered in the YugabyteDB 2.6.1 when using LDAP-based authentication in YCQL with Microsoft’s Active Directory. When anonymous or una… Yugabytedb Mitigation only Fix from $2,3002022-08-12