6.8
/ 10
MEDIUM
CVSS:4.0/AV:A/AC:H/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
Description
Shared Access Signature token is not masked in the backup configuration response and is also exposed in the yb_backup logs
AI Analysis
A vulnerability where Shared Access Signature tokens are exposed in backup configurations and logs, potentially allowing unauthorized access to sensitive data.
Basic Information
ID
CVE-2025-8864
Source
Yugabyte
Published
Aug 11, 2025 at 13:30
Affected Product
Vendor
YugabyteDB Inc
Product
YugabyteDB Anywhere
Version
2.20.0.0
Affected Versions
YugabyteDB Inc YugabyteDB Anywhere 2.23.0.0
YugabyteDB Inc YugabyteDB Anywhere 2024.1.0.0
YugabyteDB Inc YugabyteDB Anywhere 2024.1.0.0
CWE Classification
AI Assessment
AI Severity
Medium
Vendor
YugabyteDB Inc
Product
YugabyteDB Anywhere
Version
2.23.0.0, 2024.1.0.0