Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-46742

19
FAUCET Score

CVE-2023-46742 affects CubeFS, an open-source cloud-native file storage system, specifically versions prior to 3.3.1. This vulnerability involves the leakage of user secret and access keys in logs across multiple CubeFS components, particularly when new users are created. With a CVSS score of 6.5 (Medium), this flaw allows lower-privileged users to access sensitive credentials from logs, potentially enabling them to impersonate higher-privileged users. There is currently no evidence of active exploitation, nor are there public exploit modules or significant community discussion surrounding this CVE. The only mitigation is to upgrade CubeFS to version 3.3.1 or later.

Impacted Technologies

VendorProductVersion(s)CPE
< 3.3.1CPE matchmatch criteria
cpe:2.3:a:linuxfoundation:cubefs:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

4.8MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
LOW
Exploitability Score
1.3
Impact Score
3.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.27%
Probability of exploitation in next 30 days
EPSS Percentile
19.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0027 is in the 24th percentile among its peer group of 21,958 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

github_advisorypatch availablevia nvd_reference
View patch
gopatch availablevia ghsa
Product: github.com/cubefs/cubefsFixed in: 3.3.1

Vendor Advisories (1)

goGHSA-vwch-g97w-hfg2medium

CubeFS leaks users key in logs

Jan 3, 2024

References

github.com / cubefs/cubefs/commit/8dccce6ac8dff3db44d7e9074094c7303a5ff5dd
Patch
github.com / cubefs/cubefs/security/advisories/GHSA-vwch-g97w-hfg2
Third Party Advisory