CVE-2023-6002
Summary
| CVE | CVE-2023-6002 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-11-08 00:15:00 UTC |
| Updated | 2023-11-15 15:16:00 UTC |
| Description | YugabyteDB is vulnerable to cross site scripting (XSS) via log injection. Writing invalidated user input to log files can allow an attacker to forge log entries or inject malicious content into the logs. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Yugabyte | Yugabytedb | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| YugabyteDB—The Distributed SQL Database for Mission-Critical Applications | www.yugabyte.com | ||
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.