CVE-2023-0574: Server-Side Request Forgery
Server-Side Request Forgery (SSRF), Improperly Controlled Modification of Dynamically-Determined Object Attributes, Improper Restriction of Excessive Authentication Attempts vulnerability in YugaByte, Inc. Yugabyte Managed allows Accessing Functionality Not Properly Constrained by ACLs, Communication Channel Manipulation, Authentication Abuse.This issue affects Yugabyte Managed: from 2.0 through 2.13.
Other sources
Server-Side Request Forgery (SSRF), Improperly Controlled Modification of Dynamically-Determined Object Attributes, Improper Restriction of Excessive Authentication Attempts vulnerability in YugaByte, Inc. Yugabyte Managed allows Accessing Functionality Not Properly Constrained by ACLs, Communication Channel Manipulation, Authentication Abuse.This issue affects Yugabyte Managed: from 2.0.0.0 through 2.13.0.0
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-0574?
The severity of CVE-2023-0574 is critical.
What is the vulnerability description of CVE-2023-0574?
CVE-2023-0574 is a Server-Side Request Forgery (SSRF) vulnerability that allows improperly controlled modification of dynamically-determined object attributes and improper restriction of excessive authentication attempts in YugaByte, Inc. Yugabyte Managed.
What software is affected by CVE-2023-0574?
Yugabyte Yugabytedb Managed version 2.0 to 2.13 is affected by CVE-2023-0574.
How can I fix CVE-2023-0574?
To fix CVE-2023-0574, it is recommended to update YugaByte Yugabytedb Managed to a version higher than 2.13, if available.
Where can I find more information about CVE-2023-0574?
For more information about CVE-2023-0574, you can refer to the following link: [https://www.yugabyte.com/]