CVE-2023-4640

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
30/08/2023
Last modified:
05/09/2023

Description

The controller responsible for setting the logging level does not include any authorization<br /> checks to ensure the user is authenticated. This can be seen by noting that it extends<br /> Controller rather than AuthenticatedController and includes no further checks. This issue affects YugabyteDB Anywhere: from 2.0.0 through 2.17.3<br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:yugabyte:yugabytedb:*:*:*:*:*:*:*:* 2.0.0 (including) 2.17.3.0 (including)


References to Advisories, Solutions, and Tools