CVE-2023-6001: Prometheus Metrics Accessible Pre-Authentication
Published Nov 7, 2023
·Updated
Prometheus metrics are available without authentication. These expose detailed and sensitive information about the YugabyteDB Anywhere environment.
Affected Software
1 affected component
Yugabyte YugabyteDB>=2.0.0<2.18.4.0
Event History
Nov 7, 2023
CVE Published
via MITRE·11:25 PM
Data Sourced
via MITRE·11:25 PM
DescriptionSeverityWeakness
Nov 8, 2023
Data Sourced
via NVD·12:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2023-6001?
CVE-2023-6001 is a vulnerability that allows unauthorized access to Prometheus metrics in the YugabyteDB Anywhere environment.
2
How severe is CVE-2023-6001?
CVE-2023-6001 has a severity rating of high with a CVSS score of 7.5.
3
What software is affected by CVE-2023-6001?
YugabyteDB versions 2.0.0 to 2.18.4.0 are affected by CVE-2023-6001.
4
How can I fix CVE-2023-6001?
To fix CVE-2023-6001, it is recommended to update YugabyteDB to a version that is not affected by the vulnerability.
5
Where can I find more information about CVE-2023-6001?
More information about CVE-2023-6001 can be found at the Yugabyte website: https://www.yugabyte.com/