CVE-2023-40354

An issue was discovered in MariaDB MaxScale before 23.02.3. A user enters an encrypted password on a "maxctrl create service" command line, but this password is then stored in cleartext in the resulting .cnf file under /var/lib/maxscale/maxscale.cnf.d. The fixed versions are 2.5.28, 6.4.9, 22.08.8, and 23.02.3.
References
Link Resource
https://jira.mariadb.org/browse/MXS-4681 Issue Tracking Vendor Advisory
https://jira.mariadb.org/browse/MXS-4681 Issue Tracking Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mariadb:maxscale:*:*:*:*:*:*:*:*
cpe:2.3:a:mariadb:maxscale:*:*:*:*:*:*:*:*
cpe:2.3:a:mariadb:maxscale:*:*:*:*:*:*:*:*
cpe:2.3:a:mariadb:maxscale:*:*:*:*:*:*:*:*

History

21 Nov 2024, 08:19

Type Values Removed Values Added
Summary
  • (es) Se descubrió un problema en MariaDB MaxScale antes del 23.02.3. Un usuario ingresa una contraseña cifrada en una línea de comando "maxctrl create service", pero esta contraseña luego se almacena en texto sin cifrar en el archivo .cnf resultante en /var/lib/maxscale/maxscale.cnf.d. Las versiones corregidas son 2.5.28, 6.4.9, 22.08.8 y 23.02.3.
References () https://jira.mariadb.org/browse/MXS-4681 - Issue Tracking, Vendor Advisory () https://jira.mariadb.org/browse/MXS-4681 - Issue Tracking, Vendor Advisory

Information

Published : 2023-08-14 17:15

Updated : 2024-11-21 08:19


NVD link : CVE-2023-40354

Mitre link : CVE-2023-40354

CVE.ORG link : CVE-2023-40354


JSON object : View

Products Affected

mariadb

  • maxscale
CWE
CWE-312

Cleartext Storage of Sensitive Information