7
/ 10
HIGH
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:L/SA:L
Description
YugabyteDB has been collecting diagnostics information from YugabyteDB servers, which may include sensitive gflag configurations. To mitigate this, we recommend upgrading the database to a version where this information is properly redacted.
Basic Information
ID
CVE-2025-8862
Source
Yugabyte
Published
Aug 11, 2025 at 12:40
Affected Product
Vendor
YugabyteDB Inc
Product
YugabyteDB
Version
2024.1.0
Affected Versions
YugabyteDB Inc YugabyteDB 2024.1.0
YugabyteDB Inc YugabyteDB 2.20.0.0
YugabyteDB Inc YugabyteDB 2.23.0.0
YugabyteDB Inc YugabyteDB 2.20.0.0
YugabyteDB Inc YugabyteDB 2.23.0.0