CVE-2024-11165

CVSS 3.1 Score 3.9 of 10 (low)

Details

Published Nov 13, 2024
Updated: Nov 14, 2024
CWE ID 532

Summary

CVE-2024-11165 is an information disclosure vulnerability affecting YugabyteDB Anywhere. During the backup configuration process, the SAS token is not adequately masked in the response, leading to sensitive information leakage. This oversight causes the SAS token to be exposed in plaintext within the yb_backup log files. The vulnerability arises during the backup procedure and may grant unauthorized access to resources linked to the SAS token. This issue affects several YugabyteDB Anywhere versions, including those from 2.20.0.0 to 2.20.7.0, 2.23.0.0 to 2.23.1.0, and 2024.1.0.0 to 2024.1.3.0.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share