CVE Vulnerabilities

CVE-2021-22030

Insertion of Sensitive Information into Log File

Published: Nov 19, 2021 | Modified: Nov 21, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

In versions of Greenplum database prior to 5.28.14 and 6.17.0, certain statements execution led to the storage of sensitive(credential) information in the logs of the database. A malicious user with access to logs can read sensitive(credentials) information about users

Weakness

The product writes sensitive information to a log file.

Affected Software

NameVendorStart VersionEnd Version
GreenplumGreenplum*5.28.14 (excluding)
GreenplumGreenplum6.0.0 (including)6.17.0 (excluding)

Potential Mitigations

References