Prometheus metrics are available without
authentication. These expose detailed and sensitive information about the YugabyteDB Anywhere environment.
authentication. These expose detailed and sensitive information about the YugabyteDB Anywhere environment.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-58268 | Prometheus metrics are available without authentication. These expose detailed and sensitive information about the YugabyteDB Anywhere environment. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.yugabyte.com/ |
|
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Yugabyte
Published:
Updated: 2024-09-17T13:03:52.610Z
Reserved: 2023-11-07T22:19:55.387Z
Link: CVE-2023-6001
Updated: 2024-08-02T08:14:25.143Z
Status : Modified
Published: 2023-11-08T00:15:07.620
Modified: 2024-11-21T08:42:57.410
Link: CVE-2023-6001
No data.
OpenCVE Enrichment
No data.
EUVD