7
CVE-2025-8863
- EPSS 0.22%
- Veröffentlicht 11.08.2025 13:15:39
- Zuletzt bearbeitet 15.04.2026 00:35:42
- Quelle security@yugabyte.com
- CVE-Watchlists
- Unerledigt
YugabyteDB diagnostic information was transmitted over HTTP, which could expose sensitive data during transmission
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerYugabyteDB Inc
≫
Produkt
YugabyteDB
Default Statusunaffected
Version
2024.1.0
Version <
2024.1.3
Status
affected
Version
2.20.0.0
Version <
2.20.7.0
Status
affected
Version
2.23.0.0
Version <
2.23.1.0
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.22% | 0.122 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security@yugabyte.com | 7 | 0 | 0 |
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
CWE-319 Cleartext Transmission of Sensitive Information
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
https://docs.yugabyte.com/preview/secure/vulnerability-disclosure-policy/