CVE-2023-4640

Source
https://cve.org/CVERecord?id=CVE-2023-4640
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-4640.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-4640
Published
2023-08-30T16:42:45.242Z
Modified
2026-07-15T01:49:11.804939013Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N CVSS Calculator
Summary
Set Logging Level Without Authentication
Details

The controller responsible for setting the logging level does not include any authorization checks to ensure the user is authenticated. This can be seen by noting that it extends Controller rather than AuthenticatedController and includes no further checks. This issue affects YugabyteDB Anywhere: from 2.0.0 through 2.17.3

Database specific
{
    "cwe_ids": [
        "CWE-284"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/4xxx/CVE-2023-4640.json",
    "cna_assigner": "Yugabyte"
}
References

Affected packages

Git / github.com/yugabyte/yugabyte-db

Affected ranges

Type
GIT
Repo
https://github.com/yugabyte/yugabyte-db
Events
Database specific
{
    "cpe": "cpe:2.3:a:yugabyte:yugabytedb:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "2.0.0"
        },
        {
            "last_affected": "2.17.3"
        },
        {
            "last_affected": "2.17.3.0"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "CPE_RANGE"
    ]
}

Affected versions

2.*
2.17.3.0-b149
2.17.3.0-b150
2.17.3.0-b151
2.17.3.0-b152
2.17.3.0-b25_FINAL
2.17.3_FINAL
2.5.0.0
v1.*
v1.0.0-beta-yugabyted-ui
v2.*
v2.0.0
v2.0.1
v2.0.10
v2.0.11
v2.0.2
v2.0.3
v2.0.6
v2.0.7
v2.0.8
v2.0.9
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.17.3.0
v2.3.0.0
v2.3.1.0
v2.3.2.0
v2.5.1
v2.5.2
v2.5.3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-4640.json"