Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-8863

Опубликовано: 11 авг. 2025
Источник: redhat
CVSS3: 3.7
EPSS Низкий

Описание

YugabyteDB diagnostic information was transmitted over HTTP, which could expose sensitive data during transmission

An information exposure flaw has been discovered in YugabyteDB. In certain situations diagnostic information is transmitted over HTTP which could expose sensitive data to an adversary who can observe network transmissions.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss Enterprise Application Platform 8yugabytedbFix deferred
Red Hat JBoss Enterprise Application Platform Expansion PackyugabytedbFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-319
https://bugzilla.redhat.com/show_bug.cgi?id=2387620yugabytedb: YugabyteDB information exposure

EPSS

Процентиль: 15%
0.00235
Низкий

3.7 Low

CVSS3

Связанные уязвимости

nvd
около 1 года назад

YugabyteDB diagnostic information was transmitted over HTTP, which could expose sensitive data during transmission

github
около 1 года назад

YugabyteDB diagnostic information was transmitted over HTTP, which could expose sensitive data during transmission

EPSS

Процентиль: 15%
0.00235
Низкий

3.7 Low

CVSS3