CVE-2024-0006: DB User Password Leak in Application Log
Published Jul 19, 2024
·Updated
Information exposure in the logging system in Yugabyte Platform allows local attackers with access to application logs to obtain database user credentials in log files, potentially leading to unauthorized database access.
Affected Software
1 affected component
Yugabyte Yugabyte Platform
Event History
Jul 19, 2024
CVE Published
via MITRE·02:26 PM
Data Sourced
via MITRE·02:26 PM
DescriptionWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-0006?
CVE-2024-0006 has a moderate severity level due to the potential for unauthorized database access.
2
How do I fix CVE-2024-0006?
To fix CVE-2024-0006, ensure that logging systems do not expose sensitive database user credentials.
3
What systems are affected by CVE-2024-0006?
CVE-2024-0006 affects the Yugabyte Platform's logging system.
4
Who can exploit CVE-2024-0006?
Local attackers with access to application logs can exploit CVE-2024-0006 to retrieve sensitive information.
5
What kind of information is exposed by CVE-2024-0006?
CVE-2024-0006 exposes database user credentials found in application log files.