Improper privilege management in Yugabyte Platform allows authenticated admin users to escalate privileges to SuperAdmin via a crafted PUT HTTP request, potentially leading to unauthorized access to sensitive system functions and data.
[
{
"source": "https://github.com/yugabyte/yugabyte-db/commit/68f01680c565be2a370cfb7734a1b3721d6778bb",
"signature_version": "v1",
"deprecated": false,
"id": "CVE-2024-6908-0ee488bc",
"target": {
"file": "managed/src/test/java/com/yugabyte/yw/controllers/UsersControllerTest.java"
},
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"23136404727938099402094247942867305506",
"268109784697180586888374699270357321183",
"170928423322184071298563136088902474222",
"326561129504036851046669166642755468371",
"298104032484539792911617455937168306915",
"149115523116181273154637434622715853811"
]
}
},
{
"source": "https://github.com/yugabyte/yugabyte-db/commit/68f01680c565be2a370cfb7734a1b3721d6778bb",
"signature_version": "v1",
"deprecated": false,
"id": "CVE-2024-6908-2d2f8719",
"target": {
"file": "managed/src/main/java/com/yugabyte/yw/controllers/YbcController.java"
},
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"38386941464383662547969588584889867108",
"50540687600443760669488047591215787241",
"73952081617020963097355328443176244596",
"70935220895179637138702705709145497838"
]
}
},
{
"source": "https://github.com/yugabyte/yugabyte-db/commit/68f01680c565be2a370cfb7734a1b3721d6778bb",
"signature_version": "v1",
"deprecated": false,
"id": "CVE-2024-6908-834faede",
"target": {
"file": "managed/src/main/java/com/yugabyte/yw/controllers/UsersController.java"
},
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"192138964171095151355969977394648803083",
"59000782050820667527649063845504079851",
"336975985142418399781436410193887473031",
"242754815263414101816362273782782127834",
"127488467474057792402601833945847662623",
"152409963728829890162000095304891851384",
"102364447443960591539983625131565300172"
]
}
},
{
"source": "https://github.com/yugabyte/yugabyte-db/commit/68f01680c565be2a370cfb7734a1b3721d6778bb",
"signature_version": "v1",
"deprecated": false,
"id": "CVE-2024-6908-83d97e14",
"target": {
"function": "changeRole",
"file": "managed/src/main/java/com/yugabyte/yw/controllers/UsersController.java"
},
"signature_type": "Function",
"digest": {
"length": 1242.0,
"function_hash": "290251985707263117975818033644792522846"
}
},
{
"source": "https://github.com/yugabyte/yugabyte-db/commit/03b193de40b79329439bb9968a7d27a1cc57d662",
"signature_version": "v1",
"deprecated": false,
"id": "CVE-2024-6908-96bccd8f",
"target": {
"file": "managed/src/main/java/com/yugabyte/yw/controllers/UsersController.java"
},
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"192138964171095151355969977394648803083",
"150185239929966929246043502681959992876",
"48249719473128898346638968896278204201",
"93583001150838198363284357834164625722",
"240980066450593003092558615534753796318",
"30872787694841923490617795693088377474",
"306130394003671881438949679276819739079"
]
}
},
{
"source": "https://github.com/yugabyte/yugabyte-db/commit/68f01680c565be2a370cfb7734a1b3721d6778bb",
"signature_version": "v1",
"deprecated": false,
"id": "CVE-2024-6908-adaa09bc",
"target": {
"function": "create",
"file": "managed/src/main/java/com/yugabyte/yw/controllers/UsersController.java"
},
"signature_type": "Function",
"digest": {
"length": 2957.0,
"function_hash": "218473803069175361052691556291027949332"
}
},
{
"source": "https://github.com/yugabyte/yugabyte-db/commit/03b193de40b79329439bb9968a7d27a1cc57d662",
"signature_version": "v1",
"deprecated": false,
"id": "CVE-2024-6908-be44e612",
"target": {
"function": "changeRole",
"file": "managed/src/main/java/com/yugabyte/yw/controllers/UsersController.java"
},
"signature_type": "Function",
"digest": {
"length": 650.0,
"function_hash": "181171011168389764701270601946922006677"
}
},
{
"source": "https://github.com/yugabyte/yugabyte-db/commit/03b193de40b79329439bb9968a7d27a1cc57d662",
"signature_version": "v1",
"deprecated": false,
"id": "CVE-2024-6908-c584c740",
"target": {
"file": "managed/src/test/java/com/yugabyte/yw/controllers/UsersControllerTest.java"
},
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"23136404727938099402094247942867305506",
"268109784697180586888374699270357321183",
"170928423322184071298563136088902474222",
"326561129504036851046669166642755468371",
"298104032484539792911617455937168306915",
"149115523116181273154637434622715853811"
]
}
},
{
"source": "https://github.com/yugabyte/yugabyte-db/commit/03b193de40b79329439bb9968a7d27a1cc57d662",
"signature_version": "v1",
"deprecated": false,
"id": "CVE-2024-6908-d87757c9",
"target": {
"function": "create",
"file": "managed/src/main/java/com/yugabyte/yw/controllers/UsersController.java"
},
"signature_type": "Function",
"digest": {
"length": 1127.0,
"function_hash": "147296581769899178307756026745589266932"
}
}
]