Home
MEDIUM: 4.1 CVSS:4.0/AV:A/AC:H/AT:P/PR:H/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:LDefault status
unaffected
2024.1.0.0 (custom) before 2024.1.3.0
affected
2024.2.0.0 (custom) before 2024.2.2.5
affected
2.20.0.0 (custom) before 2.20.9.0
affected
Description
The YugabyteDB tablet server contains a flaw in its YCQL query handling that can trigger a null pointer dereference when processing certain malformed inputs. An authenticated attacker could exploit this issue to crash the YCQL tablet server, resulting in a denial of service.
Problem types
CWE-476 NULL Pointer Dereference
Product status
2024.1.0.0 (custom) before 2024.1.3.0
2024.2.0.0 (custom) before 2024.2.2.5
2.20.0.0 (custom) before 2.20.9.0
References
docs.yugabyte.com/...secure/vulnerability-disclosure-policy/