First published: Tue Nov 07 2023(Updated: )
Prometheus metrics are available without authentication. These expose detailed and sensitive information about the YugabyteDB Anywhere environment.
Credit: security@yugabyte.com
Affected Software | Affected Version | How to fix |
---|---|---|
>=2.0.0<2.18.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-6001 is a vulnerability that allows unauthorized access to Prometheus metrics in the YugabyteDB Anywhere environment.
CVE-2023-6001 has a severity rating of high with a CVSS score of 7.5.
YugabyteDB versions 2.0.0 to 2.18.4.0 are affected by CVE-2023-6001.
To fix CVE-2023-6001, it is recommended to update YugabyteDB to a version that is not affected by the vulnerability.
More information about CVE-2023-6001 can be found at the Yugabyte website: https://www.yugabyte.com/