Vulnerability Description
Out-of-bounds read was discovered in YDB server. An attacker could construct a query with insert statement that would allow him to read sensitive information from other memory locations or cause a crash.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ydb | Ydb | < 24.4.44 |
Related Weaknesses (CWE)
References
- https://ydb.tech/ru/docs/security-changelog#28-11-2022Vendor Advisory
- https://ydb.tech/ru/docs/security-changelog#28-11-2022Vendor Advisory
FAQ
What is CVE-2022-28228?
CVE-2022-28228 is a vulnerability with a CVSS score of 9.1 (CRITICAL). Out-of-bounds read was discovered in YDB server. An attacker could construct a query with insert statement that would allow him to read sensitive information from other memory locations or cause a cra...
How severe is CVE-2022-28228?
CVE-2022-28228 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2022-28228?
Check the references section above for vendor advisories and patch information. Affected products include: Ydb Ydb.