CVE-2024-6908

July 19, 2024, 3:15 p.m.

Received
CVE has been recently published to the CVE List and has been received by the NVD.

Products

Yugabyte Platform

Source

security@yugabyte.com

Tags

CVE-2024-6908 details

Published : July 19, 2024, 3:15 p.m.
Last Modified : July 19, 2024, 3:15 p.m.

Description

Improper privilege management in Yugabyte Platform allows authenticated admin users to escalate privileges to SuperAdmin via a crafted PUT HTTP request, potentially leading to unauthorized access to sensitive system functions and data.

CVSS Score

1 2 3 4 5 6 7 8 9 10

Weakness

Weakness Name Description
CWE-269 Improper Privilege Management The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
This website uses the NVD API, but is not approved or certified by it.