CVE-2025-8864: Yugabytedb Inc Yugabytedb Anywhere
Medium severity, CVSS 6.8. EPSS: 0.2% chance of exploitation in the next 30 days.
Shared Access Signature token is not masked in the backup configuration response and is also exposed in the yb_backup logs
Affected products
- Yugabytedb Inc Yugabytedb Anywhere: from 2.23.0.0, before 2.23.1.0 (fixed in 2.23.1.0); from 2024.1.0.0, before 2024.1.3.0 (fixed in 2024.1.3.0)
Published 2025-08-11. Last modified 2026-06-17.