Home
MEDIUM: 6.8 CVSS:4.0/AV:A/AC:H/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:NDefault status
unaffected
2.20.0.0 (custom) before 2.20.7.0
unaffected
2.23.0.0 (custom) before 2.23.1.0
affected
2024.1.0.0 (custom) before 2024.1.3.0
affected
Description
Shared Access Signature token is not masked in the backup configuration response and is also exposed in the yb_backup logs
Problem types
CWE-532 Insertion of Sensitive Information into Log File
Product status
2.20.0.0 (custom) before 2.20.7.0
2.23.0.0 (custom) before 2.23.1.0
2024.1.0.0 (custom) before 2024.1.3.0
References
docs.yugabyte.com/...secure/vulnerability-disclosure-policy/