← Back

CVE-2023-6002

nvd nist
Published: Nov 8, 2023Modified: Jun 17, 2026

JSON object

Loading...
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD

Description

YugabyteDB is vulnerable to cross site scripting (XSS) via log injection. Writing invalidated user input to log files can allow an unprivileged attacker to forge log entries or inject malicious content into the logs.

Affected (3)

Products: Yugabyte: Yugabytedb
1 product
Yugabytedb
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Yugabyte
From 2.14.0.0 to 2.14.14.0
From 2.16.0.0 to 2.16.8.0
From 2.18.0.0 to 2.18.4.0

References (2)

Source: security@yugabyte.com
Product
Source: af854a3a-2127-422b-91ae-364da2661108
Product

Timeline

No history available yet.