Cleartext Password Storage Vulnerability in MariaDB MaxScale
CVE-2023-40354
6.5MEDIUM
What is CVE-2023-40354?
A vulnerability in MariaDB MaxScale allows users to input encrypted passwords through the 'maxctrl create service' command, but these passwords are inadvertently stored in cleartext in the maxscale.cnf configuration file located at /var/lib/maxscale/maxscale.cnf.d. This security flaw poses a risk of exposing sensitive information and requires immediate attention for those using affected versions. The issue has been addressed in subsequent software updates.