CNNVD-202508-883 Information

CNNVD ID

CNNVD-202508-883

CVE-2025-8864

  • CNNVD Published: 2025-08-11

Description (Chinese)

YugabyteDB是美国Yugabyte公司的一款用于云原生应用程序的高性能事务性分布式 SQL 数据库。 YugabyteDB存在安全漏洞,该漏洞源于备份配置响应和yb_backup日志中暴露共享访问签名令牌。

Description (English)

YugabyteDB is a high-performance service distribution SQL database for cloud-based applications from Yugabyte, United States. YugabyteDB has a security loophole, which stems from the backup configuration response and the exposure of the shared access signature token in yb backup log.

Hazard Level

Critical

Vulnerability Type

其他

Affected Vendor

Yugabyte

Published

2025-08-11

Last Modified

2026-02-24

References

https://docs.yugabyte.com/preview/secure/vulnerability-disclosure-policy/ https://access.redhat.com/security/cve/cve-2025-8864

Patch

https://github.com/yugabyte/yugabyte-db/releases

Share on: