CVE-2023-52286: Infoleak
Tencent tdsqlpcloud through 1.8.5 allows unauthenticated remote attackers to discover database credentials via an index.php/api/install/getdbinfo request, a related issue to CVE-2023-42387.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-52286?
CVE-2023-52286 has been classified as a high severity vulnerability due to its potential for remote exploitation by unauthenticated attackers.
How do I fix CVE-2023-52286?
To mitigate CVE-2023-52286, update Tencent Distributed Sql to version 1.8.6 or later which addresses this vulnerability.
What type of attack does CVE-2023-52286 allow?
CVE-2023-52286 allows unauthenticated remote attackers to discover sensitive database credentials.
What versions of Tencent Distributed Sql are affected by CVE-2023-52286?
All versions of Tencent Distributed Sql up to and including 1.8.5 are affected by CVE-2023-52286.
Is there any workaround for CVE-2023-52286 if I cannot update immediately?
If an immediate update is not possible for CVE-2023-52286, consider restricting access to the affected API endpoint until a patch can be applied.