Lucene search

K
cve[email protected]CVE-2022-28228
HistoryDec 23, 2022 - 10:15 p.m.

CVE-2022-28228

2022-12-2322:15:08
CWE-125
web.nvd.nist.gov
30
cve-2022-28228
ydb server
out-of-bounds read
sensitive information leakage
crash
nvd

9.1 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

8.7 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

56.8%

Out-of-bounds read was discovered in YDB server. An attacker could construct a query with insert statement that would allow him to read sensitive information from other memory locations or cause a crash.

Affected configurations

NVD
Node
ydbydbRange<24.4.44
CPENameOperatorVersion
ydb:ydbydblt24.4.44

CNA Affected

[
  {
    "vendor": "n/a",
    "product": "YDB",
    "versions": [
      {
        "version": "All versions prior to version 22.4.44",
        "status": "affected"
      }
    ]
  }
]

9.1 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

8.7 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

56.8%

Related for CVE-2022-28228