CVE-2023-40354

CVSS V2 None CVSS V3 None
Description
An issue was discovered in MariaDB MaxScale before 23.02.3. A user enters an encrypted password on a "maxctrl create service" command line, but this password is then stored in cleartext in the resulting .cnf file under /var/lib/maxscale/maxscale.cnf.d. The fixed versions are 2.5.28, 6.4.9, 22.08.8, and 23.02.3.
Overview
  • CVE ID
  • CVE-2023-40354
  • Assigner
  • cve@mitre.org
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2023-08-14T17:15:10
  • Last Modified Date
  • 2023-08-22T15:55:45
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:mariadb:maxscale:*:*:*:*:*:*:*:* 1 OR 2.5.28
cpe:2.3:a:mariadb:maxscale:*:*:*:*:*:*:*:* 1 OR 6.0.0 6.4.9
cpe:2.3:a:mariadb:maxscale:*:*:*:*:*:*:*:* 1 OR 22.08 22.08.8
cpe:2.3:a:mariadb:maxscale:*:*:*:*:*:*:*:* 1 OR 23.02 23.02.3
References
Reference URL Reference Tags
https://jira.mariadb.org/browse/MXS-4681 Issue Tracking Vendor Advisory
History
Created Old Value New Value Data Type Notes
2023-09-06 03:42:39 Added to TrackCVE
2023-09-06 03:42:41 Weakness Enumeration new