Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8c5j-hpjp-4fw7

Опубликовано: 11 авг. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 5.1

Описание

YugabyteDB Anywhere web server does not properly enforce authentication for the /metamaster/universe API endpoint. An unauthenticated attacker could exploit this flaw to obtain server networking configuration details, including private and public IP addresses and DNS records.

YugabyteDB Anywhere web server does not properly enforce authentication for the /metamaster/universe API endpoint. An unauthenticated attacker could exploit this flaw to obtain server networking configuration details, including private and public IP addresses and DNS records.

EPSS

Процентиль: 14%
0.00048
Низкий

5.1 Medium

CVSS4

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 5.3
redhat
21 день назад

YugabyteDB Anywhere web server does not properly enforce authentication for the /metamaster/universe API endpoint. An unauthenticated attacker could exploit this flaw to obtain server networking configuration details, including private and public IP addresses and DNS records.

nvd
21 день назад

YugabyteDB Anywhere web server does not properly enforce authentication for the /metamaster/universe API endpoint. An unauthenticated attacker could exploit this flaw to obtain server networking configuration details, including private and public IP addresses and DNS records.

EPSS

Процентиль: 14%
0.00048
Низкий

5.1 Medium

CVSS4

Дефекты

CWE-200