CVE-2023-6002: Log Injection
Published Nov 7, 2023
·Updated
YugabyteDB is vulnerable to cross site scripting (XSS) via log injection. Writing invalidated user input to log files can allow an unprivileged attacker to forge log entries or inject malicious content into the logs.
Affected Software
3 affected components
Yugabyte YugabyteDB>=2.14.0.0<2.14.14.0
Yugabyte YugabyteDB>=2.16.0.0<2.16.8.0
Yugabyte YugabyteDB>=2.18.0.0<2.18.4.0
Event History
Nov 7, 2023
CVE Published
via MITRE·11:56 PM
Data Sourced
via MITRE·11:56 PM
DescriptionSeverityWeakness
Nov 8, 2023
Data Sourced
via NVD·12:15 AM
DescriptionSeverityWeaknessAffected Software