CVE-2024-26133
Last modified
CVE-2024-26133 is a medium-severity vulnerability rated 4.9/10 on the CVSS scale. EventStoreDB (ESDB) is an operational database built to store events. A vulnerability has been identified in the projections subsystem in versions 20 prior to 20.10.6, 21 prior to 21.10.11, 22 prior to 22.10.5, and 23 prior to 23.10.1. EPSS estimates a 0.61% chance of exploitation in the next 30 days.
Description
EventStoreDB (ESDB) is an operational database built to store events. A vulnerability has been identified in the projections subsystem in versions 20 prior to 20.10.6, 21 prior to 21.10.11, 22 prior to 22.10.5, and 23 prior to 23.10.1. Only database instances that use custom projections are affected by this vulnerability. User passwords may become accessible to those who have access to the chunk files on disk, and users who have read access to system streams. Only users in the `$admins` group can access system streams by default. ESDB 23.10.1, 22.10.5, 21.10.11, and 20.10.6 contain a patch for this issue. Users should upgrade EventStoreDB, reset the passwords for current and previous members of `$admins` and `$ops` groups, and, if a password was reused in any other system, reset it in those systems to a unique password to follow best practices. If an upgrade cannot be done immediately, reset the passwords for current and previous members of `$admins` and `$ops` groups. Avoid creating custom projections until the patch has been applied.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Kurrent | Eventstoredb | >= 20.10.0, < 20.10.6 |
| Kurrent | Eventstoredb | >= 21.10.0, < 21.10.11 |
| Kurrent | Eventstoredb | >= 22.10.0, < 22.10.5 |
| Kurrent | Eventstoredb | >= 23.10.0, < 23.10.1 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-26133?
How severe is CVE-2024-26133?
How do I fix CVE-2024-26133?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-26128baserCMS is a website development framework. Prior to versio…5.4
- CVE-2024-26129PrestaShop is an open-source e-commerce platform. Starting i…5.3
- CVE-2024-2613Data was not properly sanitized when decoding a QUIC ACK fra…7.5
- CVE-2024-26130cryptography is a package designed to expose cryptographic p…7.5
- CVE-2024-26131Element Android is an Android Matrix Client. Element Android…7.8
- CVE-2024-26132Element Android is an Android Matrix Client. A third-party m…3.3
- CVE-2024-26134cbor2 provides encoding and decoding for the Concise Binary …7.5
- CVE-2024-26135MeshCentral is a full computer management web site. Versions…8.8
- CVE-2024-26136kedi ElectronCord is a bot management tool for Discord. Comm…7.5
- CVE-2024-26138The XWiki licensor application, which manages and enforce ap…5.3
- CVE-2024-26139OpenCTI is an open source platform allowing organizations to…8.1
- CVE-2024-2614Memory safety bugs present in Firefox 123, Firefox ESR 115.8…8.8
Are you affected by CVE-2024-26133?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
