Vulnerability index

Browse CVEs

8 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Yugabytedb HIGH 7.5
CVE-2024-41435

YugabyteDB v2.21.1.0 was discovered to contain a buffer overflow via the "insert into" parameter.

No fix yet
Fix from $1,950 2024-09-03
Yugabytedb MEDIUM 6.1
CVE-2023-6002

YugabyteDB is vulnerable to cross site scripting (XSS) via log injection. Writing invalidated user input to log files can allow an unprivileged attac…

Fix: 2.14.14.0 / 2.16.8.0+
Fix from $1,600 2023-11-08
Yugabytedb HIGH 7.5
CVE-2023-6001

Prometheus metrics are available without authentication. These expose detailed and sensitive information about the YugabyteDB Anywhere environment.

Fix: 2.18.4.0+
Fix from $1,950 2023-11-08
Yugabytedb HIGH 7.5
CVE-2023-4640

The controller responsible for setting the logging level does not include any authorization checks to ensure the user is authenticated. This can be s…

Fix: after 2.17.3.0
Fix from $1,950 2023-08-30
Yugabytedb Managed CRITICAL 9.8
CVE-2023-0745

The High Availability functionality of Yugabyte Anywhere can be abused to write arbitrary files through the backup upload endpoint by using path trav…

Fix: after 2.13
Fix from $2,300 2023-02-09
Yugabytedb CRITICAL 9.8
CVE-2023-0575

External Control of Critical State Data, Improper Control of Generation of Code ('Code Injection') vulnerability in YugaByte, Inc. Yugabyte DB on Win…

Fix: 2.2.0.0+
Fix from $2,300 2023-02-09
Yugabytedb Managed CRITICAL 9.8
CVE-2023-0574

Server-Side Request Forgery (SSRF), Improperly Controlled Modification of Dynamically-Determined Object Attributes, Improper Restriction of Excessive…

Fix: after 2.13
Fix from $2,300 2023-02-09
Yugabytedb CRITICAL 9.8
CVE-2022-37397

An issue was discovered in the YugabyteDB 2.6.1 when using LDAP-based authentication in YCQL with Microsoft’s Active Directory. When anonymous or una…

Mitigation only
Fix from $2,300 2022-08-12