Home
HIGH: 7.0 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:L/SA:LDefault status
unaffected
2024.1.0 (custom) before 2024.1.3
affected
2.20.0.0 (custom) before 2.20.7.0
affected
2.23.0.0 (custom) before 2.23.1.0
affected
Description
YugabyteDB has been collecting diagnostics information from YugabyteDB servers, which may include sensitive gflag configurations. To mitigate this, we recommend upgrading the database to a version where this information is properly redacted.
Problem types
CWE-201 Insertion of Sensitive Information Into Sent Data
Product status
2024.1.0 (custom) before 2024.1.3
2.20.0.0 (custom) before 2.20.7.0
2.23.0.0 (custom) before 2.23.1.0
References
docs.yugabyte.com/...secure/vulnerability-disclosure-policy/