6.5
/ 10
MEDIUM
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Description
Incorrect configuration of replication security in the MariaDB component of the infra-operator in YAOOK Operator allows an on-path attacker to read database contents, potentially including credentials
Basic Information
ID
CVE-2025-14758
Source
GitLab
Published
Dec 16, 2025 at 00:33
Affected Product
Vendor
ALASCA
Product
YAOOK
Version
0.20240809.0
Affected Versions
ALASCA YAOOK 0.20240809.0