HomeDefault status
unaffected
1.0.0 (semver)
affected
Description
Reveals plaintext credentials in the MONITOR command vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from 1.0.0 through 2.13.0. Users are recommended to upgrade to version 2.14.0, which fixes the issue.
Problem types
Reveals plaintext credentials in the MONITOR command
Product status
1.0.0 (semver)
Credits
Mapta / BugBunny_ai
References
www.openwall.com/lists/oss-security/2025/11/28/3
lists.apache.org/thread/h2pcvr5p9otc7dnj2dt2nr4b3omghddw