CVE-2024-26133 is a vulnerability in EventStoreDB (ESDB) versions 20 prior to 20.10.6, 21 prior to 21.10.11, 22 prior to 22.10.5, and 23 prior to 23.10.1, specifically affecting instances utilizing custom projections. This flaw allows user passwords to become accessible to individuals with disk access to chunk files or read access to system streams, particularly those in the $admins group. Rated as Medium severity (CVSS 4.9), the vulnerability requires high privileges (PR:H) for exploitation and could lead to a complete compromise of confidentiality (C:H). There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 20.10.0, < 20.10.6CPE matchmatch criteria | cpe:2.3:a:kurrent:eventstoredb:*:*:*:*:open-source:*:*:* | ||
>= 21.10.0, < 21.10.11CPE matchmatch criteria | cpe:2.3:a:kurrent:eventstoredb:*:*:*:*:open-source:*:*:* | ||
>= 22.10.0, < 22.10.5CPE matchmatch criteria | cpe:2.3:a:kurrent:eventstoredb:*:*:*:*:open-source:*:*:* | ||
>= 23.10.0, < 23.10.1CPE matchmatch criteria | cpe:2.3:a:kurrent:eventstoredb:*:*:*:*:open-source:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.