Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-0575


External Control of Critical State Data, Improper Control of Generation of Code ('Code Injection') vulnerability in YugaByte, Inc. Yugabyte DB on Windows, Linux, MacOS, iOS (DevopsBase.Java:execCommand, TableManager.Java:runCommand modules) allows API Manipulation, Privilege Abuse. This vulnerability is associated with program files backup.Py. This issue affects Yugabyte DB: Lesser then 2.2.0.0


Published

2023-02-09T17:15:15.730

Last Modified

2024-11-21T07:37:25.707

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.2 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-94
    CWE-642
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application yugabyte yugabytedb < 2.2.0.0 Yes
Operating System apple iphone_os - No
Operating System apple macos - No
Operating System linux linux_kernel - No
Operating System microsoft windows - No

References