CVE-2023-0575
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
External Control of Critical State Data, Improper Control of Generation of Code ('Code Injection') vulnerability in YugaByte, Inc. Yugabyte DB on Windows, Linux, MacOS, iOS (DevopsBase.Java:execCommand, TableManager.Java:runCommand modules) allows API Manipulation, Privilege Abuse. This vulnerability is associated with program files backup.Py.
This issue affects Yugabyte DB: Lesser then 2.2.0.0
Affected (1)
Products: Yugabyte: Yugabytedb
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.2.0.0 |
| Running on/with | Platform Versions |
|---|---|
Apple Iphone Os | All versions |
Apple Macos | All versions |
Linux Linux Kernel | All versions |
Microsoft Windows | All versions |
Related CWEs
CWE-642
External Control of Critical State Data
The product stores security-critical state information about its users, or the product itself, in a location that is accessible to unauthorized actors.
CWE-94
Improper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
References (2)
Timeline
No history available yet.