CVE-2024-6908

Improper privilege management in Yugabyte Platform allows authenticated admin users to escalate privileges to SuperAdmin via a crafted PUT HTTP request, potentially leading to unauthorized access to sensitive system functions and data.
CVSS

No CVSS.

Configurations

No configuration.

History

21 Nov 2024, 09:50

Type Values Removed Values Added
References () https://github.com/yugabyte/yugabyte-db/commit/03b193de40b79329439bb9968a7d27a1cc57d662 - () https://github.com/yugabyte/yugabyte-db/commit/03b193de40b79329439bb9968a7d27a1cc57d662 -
References () https://github.com/yugabyte/yugabyte-db/commit/68f01680c565be2a370cfb7734a1b3721d6778bb - () https://github.com/yugabyte/yugabyte-db/commit/68f01680c565be2a370cfb7734a1b3721d6778bb -

22 Jul 2024, 13:00

Type Values Removed Values Added
Summary
  • (es) La gestión inadecuada de privilegios en la plataforma Yugabyte permite a los usuarios administradores autenticados escalar privilegios a SuperAdmin a través de una solicitud HTTP PUT manipulada, lo que podría conducir a un acceso no autorizado a funciones y datos confidenciales del sistema.

19 Jul 2024, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-19 15:15

Updated : 2024-11-21 09:50


NVD link : CVE-2024-6908

Mitre link : CVE-2024-6908

CVE.ORG link : CVE-2024-6908


JSON object : View

Products Affected

No product.

CWE
CWE-269

Improper Privilege Management