CVE-2023-4640

Published Aug 30, 2023

Last updated 3 months ago

Overview

Description
The controller responsible for setting the logging level does not include any authorization checks to ensure the user is authenticated. This can be seen by noting that it extends Controller rather than AuthenticatedController and includes no further checks. This issue affects YugabyteDB Anywhere: from 2.0.0 through 2.17.3
Source
security@yugabyte.com
NVD status
Modified

Risk scores

CVSS 3.1

Type
Primary
Base score
7.5
Impact score
3.6
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Severity
HIGH

Weaknesses

security@yugabyte.com
CWE-284
nvd@nist.gov
NVD-CWE-Other

Social media

Hype score
Not currently trending

Configurations