Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-8866

Опубликовано: 11 авг. 2025
Источник: nvd
EPSS Низкий

Описание

YugabyteDB Anywhere web server does not properly enforce authentication for the /metamaster/universe API endpoint. An unauthenticated attacker could exploit this flaw to obtain server networking configuration details, including private and public IP addresses and DNS records.

EPSS

Процентиль: 13%
0.00224
Низкий

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 5.3
redhat
около 1 года назад

YugabyteDB Anywhere web server does not properly enforce authentication for the /metamaster/universe API endpoint. An unauthenticated attacker could exploit this flaw to obtain server networking configuration details, including private and public IP addresses and DNS records.

github
около 1 года назад

YugabyteDB Anywhere web server does not properly enforce authentication for the /metamaster/universe API endpoint. An unauthenticated attacker could exploit this flaw to obtain server networking configuration details, including private and public IP addresses and DNS records.

EPSS

Процентиль: 13%
0.00224
Низкий

Дефекты

CWE-200
Уязвимость CVE-2025-8866