First published: Sun Dec 31 2023(Updated: )
Tencent tdsqlpcloud through 1.8.5 allows unauthenticated remote attackers to discover database credentials via an index.php/api/install/get_db_info request, a related issue to CVE-2023-42387.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tencent Tencent Distributed Sql | <=1.8.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-52286 has been classified as a high severity vulnerability due to its potential for remote exploitation by unauthenticated attackers.
To mitigate CVE-2023-52286, update Tencent Distributed Sql to version 1.8.6 or later which addresses this vulnerability.
CVE-2023-52286 allows unauthenticated remote attackers to discover sensitive database credentials.
All versions of Tencent Distributed Sql up to and including 1.8.5 are affected by CVE-2023-52286.
If an immediate update is not possible for CVE-2023-52286, consider restricting access to the affected API endpoint until a patch can be applied.