CVE-2021-22030

Severity CVSS v4.0:
Pending analysis
Type:
CWE-532 Information Exposure Through Log Files
Publication date:
19/11/2021
Last modified:
24/11/2021

Description

In versions of Greenplum database prior to 5.28.14 and 6.17.0, certain statements execution led to the storage of sensitive(credential) information in the logs of the database. A malicious user with access to logs can read sensitive(credentials) information about users

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:greenplum:greenplum:*:*:*:*:*:*:*:* 5.28.14 (excluding)
cpe:2.3:a:greenplum:greenplum:*:*:*:*:*:*:*:* 6.0.0 (including) 6.17.0 (excluding)