aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorbazeltsev <bazeltsev@ydb.tech>2022-12-01 14:24:39 +0300
committerbazeltsev <bazeltsev@ydb.tech>2022-12-01 14:24:39 +0300
commitd999b6bf3d7d05e72fc40475cec33946fca070af (patch)
tree7cac0fd88e5d5d34256e1cd6ce96464fc7a72115
parent7ece66569667210c20624e311166eb9852861193 (diff)
downloadydb-d999b6bf3d7d05e72fc40475cec33946fca070af.tar.gz
Add credits to security changelog
updated updated
-rw-r--r--ydb/docs/en/core/security-changelog.md4
-rw-r--r--ydb/docs/ru/core/security-changelog.md4
2 files changed, 6 insertions, 2 deletions
diff --git a/ydb/docs/en/core/security-changelog.md b/ydb/docs/en/core/security-changelog.md
index 50aadcc114d..405f673d137 100644
--- a/ydb/docs/en/core/security-changelog.md
+++ b/ydb/docs/en/core/security-changelog.md
@@ -1,9 +1,11 @@
# Security changelog
-## Fixed in YDB 22.4.44, 11.28.2022 {#28-11-2022}
+## Fixed in YDB 22.4.44, 2022-11-28 {#28-11-2022}
### CVE-2022-28228 {#cve-2022-28228}
Out-of-bounds read was discovered in YDB server. An attacker could construct a query with insert statement that would allow him to read sensitive information from other memory locations or cause a crash.
Link to CVE: [https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-28228](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-28228).
+
+Credits: Maxim Arnold.
diff --git a/ydb/docs/ru/core/security-changelog.md b/ydb/docs/ru/core/security-changelog.md
index 6b63bcdb9df..239a352bff0 100644
--- a/ydb/docs/ru/core/security-changelog.md
+++ b/ydb/docs/ru/core/security-changelog.md
@@ -1,9 +1,11 @@
# Список изменений безопасности
-## Исправлено в YDB 22.4.44, 28.11.2022 {#28-11-2022}
+## Исправлено в YDB 22.4.44, 2022-11-28 {#28-11-2022}
### CVE-2022-28228 {#cve-2022-28228}
В сервере YDB обнаружено чтение за пределами допустимого адресного пространства. Злоумышленник с помощью специально сконструированного запроса с оператором insert может получить доступ к конфиденциальной информации или вызвать сбой.
Ссылка на CVE: [https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-28228](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-28228).
+
+Обнаружено благодаря Максиму Арнольду.