Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5653-wcrh-6wrg

Опубликовано: 05 фев. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 2.4

Описание

YugabyteDB Anywhere displays LDAP bind passwords configured via gflags in cleartext within the web UI. An authenticated user with access to the configuration view could obtain LDAP credentials, potentially enabling unauthorized access to external directory services.

YugabyteDB Anywhere displays LDAP bind passwords configured via gflags in cleartext within the web UI. An authenticated user with access to the configuration view could obtain LDAP credentials, potentially enabling unauthorized access to external directory services.

EPSS

Процентиль: 4%
0.00019
Низкий

2.4 Low

CVSS4

Дефекты

CWE-522

Связанные уязвимости

nvd
3 дня назад

YugabyteDB Anywhere displays LDAP bind passwords configured via gflags in cleartext within the web UI. An authenticated user with access to the configuration view could obtain LDAP credentials, potentially enabling unauthorized access to external directory services.

EPSS

Процентиль: 4%
0.00019
Низкий

2.4 Low

CVSS4

Дефекты

CWE-522