CVE-2023-0575: Remote Code Execution
External Control of Critical State Data, Improper Control of Generation of Code ('Code Injection') vulnerability in YugaByte, Inc. Yugabyte DB on Windows, Linux, MacOS, iOS (DevopsBase.Java:execCommand, TableManager.Java:runCommand modules) allows API Manipulation, Privilege Abuse. This vulnerability is associated with program files backup.Py.
This issue affects Yugabyte DB: Lesser then 2.2.0.0
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-0575.
What is the severity of CVE-2023-0575?
The severity of CVE-2023-0575 is critical.
Which software is affected by CVE-2023-0575?
Yugabyte DB up to version 2.2.0.0 is affected by CVE-2023-0575.
How can the vulnerability be exploited?
The vulnerability can be exploited through external control of critical state data, allowing code injection, which could lead to API manipulation and privilege abuse.
Is Apple iPhone OS, Apple macOS, Linux kernel, and Microsoft Windows vulnerable to CVE-2023-0575?
No, Apple iPhone OS, Apple macOS, Linux kernel, and Microsoft Windows are not vulnerable to CVE-2023-0575.
Where can I find more information about CVE-2023-0575?
More information about CVE-2023-0575 can be found at https://www.yugabyte.com/.