Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-1966

Опубликовано: 05 фев. 2026
Источник: nvd
EPSS Низкий

Описание

YugabyteDB Anywhere displays LDAP bind passwords configured via gflags in cleartext within the web UI. An authenticated user with access to the configuration view could obtain LDAP credentials, potentially enabling unauthorized access to external directory services.

EPSS

Процентиль: 1%
0.00008
Низкий

Дефекты

CWE-522

Связанные уязвимости

CVSS3: 6.5
redhat
около 2 месяцев назад

YugabyteDB Anywhere displays LDAP bind passwords configured via gflags in cleartext within the web UI. An authenticated user with access to the configuration view could obtain LDAP credentials, potentially enabling unauthorized access to external directory services.

github
около 2 месяцев назад

YugabyteDB Anywhere displays LDAP bind passwords configured via gflags in cleartext within the web UI. An authenticated user with access to the configuration view could obtain LDAP credentials, potentially enabling unauthorized access to external directory services.

EPSS

Процентиль: 1%
0.00008
Низкий

Дефекты

CWE-522