Lucene search

K
osvGoogleOSV:CVE-2023-4640
HistoryAug 30, 2023 - 5:15 p.m.

CVE-2023-4640

2023-08-3017:15:11
Google
osv.dev
8
logging level
authentication checks
yugabytedb anywhere
software
cve-2023-4640

7.1 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

37.3%

The controller responsible for setting the logging level does not include any authorization
checks to ensure the user is authenticated. This can be seen by noting that it extends
Controller rather than AuthenticatedController and includes no further checks. This issue affects YugabyteDB Anywhere: from 2.0.0 through 2.17.3

7.1 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

37.3%

Related for OSV:CVE-2023-4640