CVE-2025-8866: Infoleak
YugabyteDB Anywhere web server does not properly enforce authentication for the /metamaster/universe API endpoint. An unauthenticated attacker could exploit this flaw to obtain server networking configuration details, including private and public IP addresses and DNS records.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8866?
CVE-2025-8866 has been assessed as a critical vulnerability due to its potential for information disclosure.
How do I fix CVE-2025-8866?
To mitigate CVE-2025-8866, ensure proper authentication is enforced for the /metamaster/universe API endpoint in YugabyteDB Anywhere.
Who is affected by CVE-2025-8866?
CVE-2025-8866 affects users of YugabyteDB Anywhere that do not have authentication properly configured.
What can an attacker do with CVE-2025-8866?
An attacker exploiting CVE-2025-8866 can access sensitive server networking configuration details, including private and public IP addresses.
When was CVE-2025-8866 disclosed?
CVE-2025-8866 was publicly disclosed as part of ongoing vulnerability assessments for YugabyteDB Anywhere.