Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-8866

Опубликовано: 11 авг. 2025
Источник: nvd
EPSS Низкий

Описание

YugabyteDB Anywhere web server does not properly enforce authentication for the /metamaster/universe API endpoint. An unauthenticated attacker could exploit this flaw to obtain server networking configuration details, including private and public IP addresses and DNS records.

EPSS

Процентиль: 14%
0.00048
Низкий

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 5.3
redhat
18 дней назад

YugabyteDB Anywhere web server does not properly enforce authentication for the /metamaster/universe API endpoint. An unauthenticated attacker could exploit this flaw to obtain server networking configuration details, including private and public IP addresses and DNS records.

github
18 дней назад

YugabyteDB Anywhere web server does not properly enforce authentication for the /metamaster/universe API endpoint. An unauthenticated attacker could exploit this flaw to obtain server networking configuration details, including private and public IP addresses and DNS records.

EPSS

Процентиль: 14%
0.00048
Низкий

Дефекты

CWE-200