Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-8866

Опубликовано: 11 авг. 2025
Источник: nvd
EPSS Низкий

Описание

YugabyteDB Anywhere web server does not properly enforce authentication for the /metamaster/universe API endpoint. An unauthenticated attacker could exploit this flaw to obtain server networking configuration details, including private and public IP addresses and DNS records.

EPSS

Процентиль: 22%
0.00074
Низкий

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 5.3
redhat
6 месяцев назад

YugabyteDB Anywhere web server does not properly enforce authentication for the /metamaster/universe API endpoint. An unauthenticated attacker could exploit this flaw to obtain server networking configuration details, including private and public IP addresses and DNS records.

github
6 месяцев назад

YugabyteDB Anywhere web server does not properly enforce authentication for the /metamaster/universe API endpoint. An unauthenticated attacker could exploit this flaw to obtain server networking configuration details, including private and public IP addresses and DNS records.

EPSS

Процентиль: 22%
0.00074
Низкий

Дефекты

CWE-200