Search
Find a vulnerability
Search criteria
2 vulnerabilities found for yugabytedb_anywhere by yugabytedb
CVE-2024-6908 (GCVE-0-2024-6908)
Vulnerability from nvd – Published: 2024-07-19 14:57 – Updated: 2024-08-01 21:45
VLAI
EPSS
VEX
Title
Admin Can Escalate Privileges to SuperAdmin Using Manual PUT Request
Summary
Improper privilege management in Yugabyte Platform allows authenticated admin users to escalate privileges to SuperAdmin via a crafted PUT HTTP request, potentially leading to unauthorized access to sensitive system functions and data.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2024-07-23 20:27 UTC
CWE
- CWE-269 - Improper Privilege Management
Assigner
References
2 references
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| YugabyteDB | YugabyteDB Anywhere |
Affected:
2.14.0.0 , ≤ 2.14.17.0
(git)
Affected: 2.16.0.0 , ≤ 2.16.9.0 (git) Affected: 2.18.0.0 , < 2.18.7.0 (git) Affected: 2.20.0.0 , < 2.20.3.0 (git) |
|
| yugabytedb | yugabytedb_anywhere |
Affected:
2.14.0.0 , ≤ 2.14.17.0
(git)
Affected: 2.16.0.0 , ≤ 2.16.9.0 (git) Affected: 2.18.0.0 , < 2.18.7.0 (git) Affected: 2.20.0.0 , < 2.20.3.0 (git) cpe:2.3:a:yugabytedb:yugabytedb_anywhere:*:*:*:*:*:*:*:* |
Date Public
2024-07-18 21:48
{
"containers": {
"adp": [
{
"affected": [
{
"cpes": [
"cpe:2.3:a:yugabytedb:yugabytedb_anywhere:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unaffected",
"product": "yugabytedb_anywhere",
"vendor": "yugabytedb",
"versions": [
{
"lessThanOrEqual": "2.14.17.0",
"status": "affected",
"version": "2.14.0.0",
"versionType": "git"
},
{
"lessThanOrEqual": "2.16.9.0",
"status": "affected",
"version": "2.16.0.0",
"versionType": "git"
},
{
"lessThan": "2.18.7.0",
"status": "affected",
"version": "2.18.0.0",
"versionType": "git"
},
{
"lessThan": "2.20.3.0",
"status": "affected",
"version": "2.20.0.0",
"versionType": "git"
}
]
}
],
"metrics": [
{
"other": {
"content": {
"id": "CVE-2024-6908",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2024-07-23T20:27:45.607511Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2024-07-23T20:36:54.209Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
},
{
"providerMetadata": {
"dateUpdated": "2024-08-01T21:45:38.372Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"patch",
"x_transferred"
],
"url": "https://github.com/yugabyte/yugabyte-db/commit/03b193de40b79329439bb9968a7d27a1cc57d662"
},
{
"tags": [
"patch",
"x_transferred"
],
"url": "https://github.com/yugabyte/yugabyte-db/commit/68f01680c565be2a370cfb7734a1b3721d6778bb"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"platforms": [
"Linux",
"Docker",
"Kubernetes"
],
"product": "YugabyteDB Anywhere",
"vendor": "YugabyteDB",
"versions": [
{
"lessThanOrEqual": "2.14.17.0",
"status": "affected",
"version": "2.14.0.0",
"versionType": "git"
},
{
"lessThanOrEqual": "2.16.9.0",
"status": "affected",
"version": "2.16.0.0",
"versionType": "git"
},
{
"lessThan": "2.18.7.0",
"status": "affected",
"version": "2.18.0.0",
"versionType": "git"
},
{
"lessThan": "2.20.3.0",
"status": "affected",
"version": "2.20.0.0",
"versionType": "git"
}
]
}
],
"datePublic": "2024-07-18T21:48:00.000Z",
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Improper privilege management in Yugabyte Platform allows authenticated admin users to escalate privileges to SuperAdmin via a crafted PUT HTTP request, potentially leading to unauthorized access to sensitive system functions and data."
}
],
"value": "Improper privilege management in Yugabyte Platform allows authenticated admin users to escalate privileges to SuperAdmin via a crafted PUT HTTP request, potentially leading to unauthorized access to sensitive system functions and data."
}
],
"impacts": [
{
"capecId": "CAPEC-233",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-233 Privilege Escalation"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "ADJACENT",
"baseScore": 6,
"baseSeverity": "MEDIUM",
"privilegesRequired": "HIGH",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "HIGH",
"subConfidentialityImpact": "HIGH",
"subIntegrityImpact": "HIGH",
"userInteraction": "PASSIVE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:A/AC:L/AT:P/PR:H/UI:P/VC:L/VI:H/VA:N/SC:H/SI:H/SA:H",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-269",
"description": "CWE-269 Improper Privilege Management",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2024-07-19T14:57:00.607Z",
"orgId": "d4ae51d3-4db5-465e-bc8a-eb6768324078",
"shortName": "Yugabyte"
},
"references": [
{
"tags": [
"patch"
],
"url": "https://github.com/yugabyte/yugabyte-db/commit/03b193de40b79329439bb9968a7d27a1cc57d662"
},
{
"tags": [
"patch"
],
"url": "https://github.com/yugabyte/yugabyte-db/commit/68f01680c565be2a370cfb7734a1b3721d6778bb"
}
],
"source": {
"defect": [
"PLAT-10470"
],
"discovery": "UNKNOWN"
},
"title": "Admin Can Escalate Privileges to SuperAdmin Using Manual PUT Request",
"x_generator": {
"engine": "Vulnogram 0.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "d4ae51d3-4db5-465e-bc8a-eb6768324078",
"assignerShortName": "Yugabyte",
"cveId": "CVE-2024-6908",
"datePublished": "2024-07-19T14:57:00.607Z",
"dateReserved": "2024-07-18T21:27:07.259Z",
"dateUpdated": "2024-08-01T21:45:38.372Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2024-6908 (GCVE-0-2024-6908)
Vulnerability from cvelistv5 – Published: 2024-07-19 14:57 – Updated: 2024-08-01 21:45
VLAI
EPSS
VEX
Title
Admin Can Escalate Privileges to SuperAdmin Using Manual PUT Request
Summary
Improper privilege management in Yugabyte Platform allows authenticated admin users to escalate privileges to SuperAdmin via a crafted PUT HTTP request, potentially leading to unauthorized access to sensitive system functions and data.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2024-07-23 20:27 UTC
CWE
- CWE-269 - Improper Privilege Management
Assigner
References
2 references
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| YugabyteDB | YugabyteDB Anywhere |
Affected:
2.14.0.0 , ≤ 2.14.17.0
(git)
Affected: 2.16.0.0 , ≤ 2.16.9.0 (git) Affected: 2.18.0.0 , < 2.18.7.0 (git) Affected: 2.20.0.0 , < 2.20.3.0 (git) |
|
| yugabytedb | yugabytedb_anywhere |
Affected:
2.14.0.0 , ≤ 2.14.17.0
(git)
Affected: 2.16.0.0 , ≤ 2.16.9.0 (git) Affected: 2.18.0.0 , < 2.18.7.0 (git) Affected: 2.20.0.0 , < 2.20.3.0 (git) cpe:2.3:a:yugabytedb:yugabytedb_anywhere:*:*:*:*:*:*:*:* |
Date Public
2024-07-18 21:48
{
"containers": {
"adp": [
{
"affected": [
{
"cpes": [
"cpe:2.3:a:yugabytedb:yugabytedb_anywhere:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unaffected",
"product": "yugabytedb_anywhere",
"vendor": "yugabytedb",
"versions": [
{
"lessThanOrEqual": "2.14.17.0",
"status": "affected",
"version": "2.14.0.0",
"versionType": "git"
},
{
"lessThanOrEqual": "2.16.9.0",
"status": "affected",
"version": "2.16.0.0",
"versionType": "git"
},
{
"lessThan": "2.18.7.0",
"status": "affected",
"version": "2.18.0.0",
"versionType": "git"
},
{
"lessThan": "2.20.3.0",
"status": "affected",
"version": "2.20.0.0",
"versionType": "git"
}
]
}
],
"metrics": [
{
"other": {
"content": {
"id": "CVE-2024-6908",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2024-07-23T20:27:45.607511Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2024-07-23T20:36:54.209Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
},
{
"providerMetadata": {
"dateUpdated": "2024-08-01T21:45:38.372Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"patch",
"x_transferred"
],
"url": "https://github.com/yugabyte/yugabyte-db/commit/03b193de40b79329439bb9968a7d27a1cc57d662"
},
{
"tags": [
"patch",
"x_transferred"
],
"url": "https://github.com/yugabyte/yugabyte-db/commit/68f01680c565be2a370cfb7734a1b3721d6778bb"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"platforms": [
"Linux",
"Docker",
"Kubernetes"
],
"product": "YugabyteDB Anywhere",
"vendor": "YugabyteDB",
"versions": [
{
"lessThanOrEqual": "2.14.17.0",
"status": "affected",
"version": "2.14.0.0",
"versionType": "git"
},
{
"lessThanOrEqual": "2.16.9.0",
"status": "affected",
"version": "2.16.0.0",
"versionType": "git"
},
{
"lessThan": "2.18.7.0",
"status": "affected",
"version": "2.18.0.0",
"versionType": "git"
},
{
"lessThan": "2.20.3.0",
"status": "affected",
"version": "2.20.0.0",
"versionType": "git"
}
]
}
],
"datePublic": "2024-07-18T21:48:00.000Z",
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Improper privilege management in Yugabyte Platform allows authenticated admin users to escalate privileges to SuperAdmin via a crafted PUT HTTP request, potentially leading to unauthorized access to sensitive system functions and data."
}
],
"value": "Improper privilege management in Yugabyte Platform allows authenticated admin users to escalate privileges to SuperAdmin via a crafted PUT HTTP request, potentially leading to unauthorized access to sensitive system functions and data."
}
],
"impacts": [
{
"capecId": "CAPEC-233",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-233 Privilege Escalation"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "ADJACENT",
"baseScore": 6,
"baseSeverity": "MEDIUM",
"privilegesRequired": "HIGH",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "HIGH",
"subConfidentialityImpact": "HIGH",
"subIntegrityImpact": "HIGH",
"userInteraction": "PASSIVE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:A/AC:L/AT:P/PR:H/UI:P/VC:L/VI:H/VA:N/SC:H/SI:H/SA:H",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-269",
"description": "CWE-269 Improper Privilege Management",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2024-07-19T14:57:00.607Z",
"orgId": "d4ae51d3-4db5-465e-bc8a-eb6768324078",
"shortName": "Yugabyte"
},
"references": [
{
"tags": [
"patch"
],
"url": "https://github.com/yugabyte/yugabyte-db/commit/03b193de40b79329439bb9968a7d27a1cc57d662"
},
{
"tags": [
"patch"
],
"url": "https://github.com/yugabyte/yugabyte-db/commit/68f01680c565be2a370cfb7734a1b3721d6778bb"
}
],
"source": {
"defect": [
"PLAT-10470"
],
"discovery": "UNKNOWN"
},
"title": "Admin Can Escalate Privileges to SuperAdmin Using Manual PUT Request",
"x_generator": {
"engine": "Vulnogram 0.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "d4ae51d3-4db5-465e-bc8a-eb6768324078",
"assignerShortName": "Yugabyte",
"cveId": "CVE-2024-6908",
"datePublished": "2024-07-19T14:57:00.607Z",
"dateReserved": "2024-07-18T21:27:07.259Z",
"dateUpdated": "2024-08-01T21:45:38.372Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}