CVE-2024-11165: Medium severity Yugabyte YugabyteDB Anywhere vulnerability

Published Nov 13, 2024
·
Updated

An information disclosure vulnerability exists in the backup configuration process where the SAS token is not masked in the configuration response. This oversight results in sensitive information leakage within the ybbackup log files, exposing the SAS token in plaintext. The leakage occurs during the backup procedure, leading to potential unauthorized access to resources associated with the SAS token. This issue affects YugabyteDB Anywhere: from 2.20.0.0 before 2.20.7.0, from 2.23.0.0 before 2.23.1.0, from 2024.1.0.0 before 2024.1.3.0.

Affected Software

1 affected component
Yugabyte YugabyteDB Anywhere>=2.20.0.0<2.20.7.0, >=2.23.0.0<2.23.1.0, >=2024.1.0.0<2024.1.3.0

Event History

Nov 13, 2024
CVE Published
via MITRE·02:19 PM
Data Sourced
via MITRE·02:19 PM
DescriptionWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2024-11165?

CVE-2024-11165 is an information disclosure vulnerability that can lead to exposure of sensitive SAS token information.

2

How do I fix CVE-2024-11165?

To fix CVE-2024-11165, update your YugabyteDB Anywhere to a version beyond the vulnerable ranges specified.

3

What software versions are affected by CVE-2024-11165?

CVE-2024-11165 affects specific versions of YugabyteDB Anywhere including those between 2.20.0.0 and 2.20.7.0, 2.23.0.0 and 2.23.1.0, and 2024.1.0.0 and 2024.1.3.0.

4

What sensitive information is leaked in CVE-2024-11165?

CVE-2024-11165 leads to the leakage of SAS token information in plaintext in the yb_backup log files.

5

Is CVE-2024-11165 exploitable remotely?

CVE-2024-11165 primarily results in information disclosure rather than exploitation, but the leakage can pose a risk if the exposed SAS token is misused.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203