YugabyteDB is vulnerable to cross site scripting (XSS) via log injection. Writing invalidated user input to log files can allow an unprivileged attacker to forge log entries or inject malicious content into the logs.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://www.yugabyte.com/ |
History
No history.
MITRE
Status: PUBLISHED
Assigner: Yugabyte
Published: 2023-11-07T23:56:50.729Z
Updated: 2024-09-17T13:03:18.141Z
Reserved: 2023-11-07T22:20:00.534Z
Link: CVE-2023-6002
Vulnrichment
Updated: 2024-08-02T08:14:25.135Z
NVD
Status : Modified
Published: 2023-11-08T00:15:08.360
Modified: 2024-11-21T08:42:57.553
Link: CVE-2023-6002
Redhat
No data.