CVE-2023-40354
14.08.2023, 17:15
An issue was discovered in MariaDB MaxScale before 23.02.3. A user enters an encrypted password on a "maxctrl create service" command line, but this password is then stored in cleartext in the resulting .cnf file under /var/lib/maxscale/maxscale.cnf.d. The fixed versions are 2.5.28, 6.4.9, 22.08.8, and 23.02.3.Enginsight
Vendor | Product | Version |
---|---|---|
mariadb | maxscale | 𝑥 < 2.5.28 |
mariadb | maxscale | 6.0.0 ≤ 𝑥 < 6.4.9 |
mariadb | maxscale | 22.08 ≤ 𝑥 < 22.08.8 |
mariadb | maxscale | 23.02 ≤ 𝑥 < 23.02.3 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration