Lucene search

K
nvd[email protected]NVD:CVE-2022-28228
HistoryDec 23, 2022 - 10:15 p.m.

CVE-2022-28228

2022-12-2322:15:08
CWE-125
web.nvd.nist.gov
3
ydb server
out-of-bounds read
sensitive information disclosure
memory locations
query
insert statement
crash
cve-2022-28228

9.1 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

0.002 Low

EPSS

Percentile

56.8%

Out-of-bounds read was discovered in YDB server. An attacker could construct a query with insert statement that would allow him to read sensitive information from other memory locations or cause a crash.

Affected configurations

NVD
Node
ydbydbRange<24.4.44

9.1 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

0.002 Low

EPSS

Percentile

56.8%

Related for NVD:CVE-2022-28228