CVE-2023-6002: Yugabyte Yugabytedb
Medium severity, CVSS 6.1. EPSS: 0.4% chance of exploitation in the next 30 days.
YugabyteDB is vulnerable to cross site scripting (XSS) via log injection. Writing invalidated user input to log files can allow an unprivileged attacker to forge log entries or inject malicious content into the logs.
Affected products
- Yugabyte Yugabytedb: from 2.14.0.0, before 2.14.14.0 (fixed in 2.14.14.0); from 2.16.0.0, before 2.16.8.0 (fixed in 2.16.8.0); from 2.18.0.0, before 2.18.4.0 (fixed in 2.18.4.0)
Published 2023-11-08. Last modified 2026-06-17.