CVE-2024-0006
Last modified
CVE-2024-0006 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. Information exposure in the logging system in Yugabyte Platform allows local attackers with access to application logs to obtain database user credentials in log files, potentially leading to unauthorized database access.. EPSS estimates a 0.27% chance of exploitation in the next 30 days.
Description
Information exposure in the logging system in Yugabyte Platform allows local attackers with access to application logs to obtain database user credentials in log files, potentially leading to unauthorized database access.
Metrics
CVSS:4.0/AV:A/AC:H/AT:N/PR:H/UI:A/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-0006?
How severe is CVE-2024-0006?
How do I fix CVE-2024-0006?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-0001A condition exists in FlashArray Purity whereby a local acco…9.8
- CVE-2024-0002A condition exists in FlashArray Purity whereby an attacker …9.8
- CVE-2024-0003A condition exists in FlashArray Purity whereby a malicious …7.2
- CVE-2024-0004A condition exists in FlashArray Purity whereby an user with…7.2
- CVE-2024-0005A condition exists in FlashArray and FlashBlade Purity where…8.8
- CVE-2024-0007A cross-site scripting (XSS) vulnerability in Palo Alto Netw…4.8
- CVE-2024-0008Web sessions in the management interface in Palo Alto Networ…8.8
- CVE-2024-0009An improper verification vulnerability in the GlobalProtect …6.3
- CVE-2024-0010A reflected cross-site scripting (XSS) vulnerability in the …6.1
- CVE-2024-0011A reflected cross-site scripting (XSS) vulnerability in the …6.1
- CVE-2024-0012An authentication bypass in Palo Alto Networks PAN-OS softwa…9.8
Are you affected by CVE-2024-0006?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
