CVE-2023-6001: Yugabyte Yugabytedb

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

Prometheus metrics are available without authentication. These expose detailed and sensitive information about the YugabyteDB Anywhere environment.

Affected products

  • Yugabyte Yugabytedb: from 2.0.0, before 2.18.4.0 (fixed in 2.18.4.0)

Published 2023-11-08. Last modified 2026-06-17.