YugabyteDB is vulnerable to cross site scripting (XSS) via log injection. Writing invalidated user input to log files can allow an unprivileged attacker to forge log entries or inject malicious content into the logs.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-58269 | YugabyteDB is vulnerable to cross site scripting (XSS) via log injection. Writing invalidated user input to log files can allow an unprivileged attacker to forge log entries or inject malicious content into the logs. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.yugabyte.com/ |
|
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Yugabyte
Published:
Updated: 2024-09-17T13:03:18.141Z
Reserved: 2023-11-07T22:20:00.534Z
Link: CVE-2023-6002
Updated: 2024-08-02T08:14:25.135Z
Status : Modified
Published: 2023-11-08T00:15:08.360
Modified: 2024-11-21T08:42:57.553
Link: CVE-2023-6002
No data.
OpenCVE Enrichment
No data.
EUVD