First published: Fri Nov 19 2021(Updated: )
In versions of Greenplum database prior to 5.28.14 and 6.17.0, certain statements execution led to the storage of sensitive(credential) information in the logs of the database. A malicious user with access to logs can read sensitive(credentials) information about users
Credit: security@vmware.com
Affected Software | Affected Version | How to fix |
---|---|---|
Greenplum | <5.28.14 | |
Greenplum | >=6.0.0<6.17.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-22030 is classified as a medium severity vulnerability due to the potential exposure of sensitive credentials.
To fix CVE-2021-22030, upgrade to Greenplum versions 5.28.14 or 6.17.0 or later.
CVE-2021-22030 affects sensitive credential information that may be logged during the execution of certain statements.
Any user of Greenplum database versions prior to 5.28.14 and between 6.0.0 and 6.17.0 is vulnerable to CVE-2021-22030.
The implications of CVE-2021-22030 include the risk of credential leakage, which could lead to unauthorized access to user accounts.