CVE-2024-0006: Yugabyte Yugabytedb

Medium severity, CVSS 5.4. EPSS: 0.3% chance of exploitation in the next 30 days.

Information exposure in the logging system in Yugabyte Platform allows local attackers with access to application logs to obtain database user credentials in log files, potentially leading to unauthorized database access.

Affected products

  • Yugabyte Yugabytedb: from 2.18.0.0, before 2.18.9.0 (fixed in 2.18.9.0); from 2.20.0.0, before 2.20.2.3 (fixed in 2.20.2.3); from 2024.0.0.0, before 2024.1.1.0 (fixed in 2024.1.1.0)
  • Yugabytedb Yugabytedb Anywhere

Published 2024-07-19. Last modified 2026-06-17.