First published: Tue Nov 07 2023(Updated: )
YugabyteDB is vulnerable to cross site scripting (XSS) via log injection. Writing invalidated user input to log files can allow an unprivileged attacker to forge log entries or inject malicious content into the logs.
Credit: security@yugabyte.com
Affected Software | Affected Version | How to fix |
---|---|---|
Yugabyte YugabyteDB | >=2.14.0.0<2.14.14.0 | |
Yugabyte YugabyteDB | >=2.16.0.0<2.16.8.0 | |
Yugabyte YugabyteDB | >=2.18.0.0<2.18.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.