checks to ensure the user is authenticated. This can be seen by noting that it extends
Controller rather than AuthenticatedController and includes no further checks. This issue affects YugabyteDB Anywhere: from 2.0.0 through 2.17.3
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-54492 | The controller responsible for setting the logging level does not include any authorization checks to ensure the user is authenticated. This can be seen by noting that it extends Controller rather than AuthenticatedController and includes no further checks. This issue affects YugabyteDB Anywhere: from 2.0.0 through 2.17.3 |
| Link | Providers |
|---|---|
| https://www.yugabyte.com/ |
|
Tue, 01 Oct 2024 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Yugabyte
Published:
Updated: 2024-10-01T18:31:56.957Z
Reserved: 2023-08-30T16:41:56.711Z
Link: CVE-2023-4640
Updated: 2024-08-02T07:31:06.630Z
Status : Modified
Published: 2023-08-30T17:15:11.157
Modified: 2024-11-21T08:35:35.697
Link: CVE-2023-4640
No data.
OpenCVE Enrichment
No data.
EUVD