CVE-2024-11165: Medium severity Yugabyte YugabyteDB Anywhere vulnerability
An information disclosure vulnerability exists in the backup configuration process where the SAS token is not masked in the configuration response. This oversight results in sensitive information leakage within the ybbackup log files, exposing the SAS token in plaintext. The leakage occurs during the backup procedure, leading to potential unauthorized access to resources associated with the SAS token. This issue affects YugabyteDB Anywhere: from 2.20.0.0 before 2.20.7.0, from 2.23.0.0 before 2.23.1.0, from 2024.1.0.0 before 2024.1.3.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-11165?
CVE-2024-11165 is an information disclosure vulnerability that can lead to exposure of sensitive SAS token information.
How do I fix CVE-2024-11165?
To fix CVE-2024-11165, update your YugabyteDB Anywhere to a version beyond the vulnerable ranges specified.
What software versions are affected by CVE-2024-11165?
CVE-2024-11165 affects specific versions of YugabyteDB Anywhere including those between 2.20.0.0 and 2.20.7.0, 2.23.0.0 and 2.23.1.0, and 2024.1.0.0 and 2024.1.3.0.
What sensitive information is leaked in CVE-2024-11165?
CVE-2024-11165 leads to the leakage of SAS token information in plaintext in the yb_backup log files.
Is CVE-2024-11165 exploitable remotely?
CVE-2024-11165 primarily results in information disclosure rather than exploitation, but the leakage can pose a risk if the exposed SAS token is misused.