NVD Vulnerability Detail
Search Exploit, PoC
CVE-2024-11193
Summary

An information disclosure vulnerability exists in Yugabyte Anywhere, where the LDAP bind password is logged in plaintext within application logs. This flaw results in the unintentional exposure of sensitive information in Yugabyte Anywhere logs, potentially allowing unauthorized users with access to these logs to view the LDAP bind password. An attacker with log access could exploit this vulnerability to gain unauthorized access to the LDAP server, leading to potential exposure or compromise of LDAP-managed resources
This issue affects YugabyteDB Anywhere: from 2.20.0.0 before 2.20.7.0, from 2.23.0.0 before 2.23.1.0, from 2024.1.0.0 before 2024.1.3.0.

Publication Date Nov. 14, 2024, 6:15 a.m.
Registration Date Nov. 14, 2024, 12:01 p.m.
Last Update Nov. 15, 2024, 11 p.m.
Related information, measures and tools
Common Vulnerabilities List