Cleartext Password Storage Vulnerability in MariaDB MaxScale
CVE-2023-40354

6.5MEDIUM

Key Information:

Vendor

Mariadb

Status
Vendor
CVE Published:
14 August 2023

What is CVE-2023-40354?

A vulnerability in MariaDB MaxScale allows users to input encrypted passwords through the 'maxctrl create service' command, but these passwords are inadvertently stored in cleartext in the maxscale.cnf configuration file located at /var/lib/maxscale/maxscale.cnf.d. This security flaw poses a risk of exposing sensitive information and requires immediate attention for those using affected versions. The issue has been addressed in subsequent software updates.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.