VendorsYugabyteyugabytedball versions
Vulnerabilities

Yugabyte DB

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2022-37397
The software is vulnerable when using LDAP-based authentication in YCQL with Microsoft’s Active Directory
Published 2022-08-12 · Modified
9.8EPSS 0.009
CVE-2023-0575
Remote Code Execution
Published 2023-02-09 · Modified
9.8EPSS 0.008
CVE-2023-6001
Prometheus Metrics Accessible Pre-Authentication
Published 2023-11-07 · Modified
7.5EPSS 0.006
CVE-2024-41435
YugabyteDB v2.21.1.0 was discovered to contain a buffer overflow via the "insert into" parameter.
Published 2024-09-03 · Analyzed
7.5EPSS 0.005
CVE-2023-4640
Set Logging Level Without Authentication
Published 2023-08-30 · Modified
7.5EPSS 0.004
CVE-2023-6002
Log Injection
Published 2023-11-07 · Modified
6.5EPSS 0.004