Lucene search

K
cvelistYugabyteCVELIST:CVE-2023-6001
HistoryNov 07, 2023 - 11:25 p.m.

CVE-2023-6001 Prometheus Metrics Accessible Pre-Authentication

2023-11-0723:25:16
CWE-200
Yugabyte
www.cve.org
1
prometheus metrics
authentication
sensitive information
yugabytedb anywhere environment

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

0.001 Low

EPSS

Percentile

37.3%

Prometheus metrics are available without
authentication. These expose detailed and sensitive information about the YugabyteDB Anywhere environment.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "platforms": [
      "Linux",
      "Docker",
      "Kubernetes"
    ],
    "product": "YugabyteDB Anywhere",
    "vendor": "YugabyteDB",
    "versions": [
      {
        "lessThanOrEqual": "2.18.3.0",
        "status": "affected",
        "version": "2.0.0.0",
        "versionType": "semver"
      },
      {
        "status": "unaffected",
        "version": "2.18.4.0"
      },
      {
        "status": "unaffected",
        "version": "2.20.0.0"
      }
    ]
  }
]

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

0.001 Low

EPSS

Percentile

37.3%

Related for CVELIST:CVE-2023-6001