diff options
author | bazeltsev <bazeltsev@ydb.tech> | 2022-12-01 14:24:39 +0300 |
---|---|---|
committer | bazeltsev <bazeltsev@ydb.tech> | 2022-12-01 14:24:39 +0300 |
commit | d999b6bf3d7d05e72fc40475cec33946fca070af (patch) | |
tree | 7cac0fd88e5d5d34256e1cd6ce96464fc7a72115 | |
parent | 7ece66569667210c20624e311166eb9852861193 (diff) | |
download | ydb-d999b6bf3d7d05e72fc40475cec33946fca070af.tar.gz |
Add credits to security changelog
updated
updated
-rw-r--r-- | ydb/docs/en/core/security-changelog.md | 4 | ||||
-rw-r--r-- | ydb/docs/ru/core/security-changelog.md | 4 |
2 files changed, 6 insertions, 2 deletions
diff --git a/ydb/docs/en/core/security-changelog.md b/ydb/docs/en/core/security-changelog.md index 50aadcc114d..405f673d137 100644 --- a/ydb/docs/en/core/security-changelog.md +++ b/ydb/docs/en/core/security-changelog.md @@ -1,9 +1,11 @@ # Security changelog -## Fixed in YDB 22.4.44, 11.28.2022 {#28-11-2022} +## Fixed in YDB 22.4.44, 2022-11-28 {#28-11-2022} ### CVE-2022-28228 {#cve-2022-28228} Out-of-bounds read was discovered in YDB server. An attacker could construct a query with insert statement that would allow him to read sensitive information from other memory locations or cause a crash. Link to CVE: [https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-28228](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-28228). + +Credits: Maxim Arnold. diff --git a/ydb/docs/ru/core/security-changelog.md b/ydb/docs/ru/core/security-changelog.md index 6b63bcdb9df..239a352bff0 100644 --- a/ydb/docs/ru/core/security-changelog.md +++ b/ydb/docs/ru/core/security-changelog.md @@ -1,9 +1,11 @@ # Список изменений безопасности -## Исправлено в YDB 22.4.44, 28.11.2022 {#28-11-2022} +## Исправлено в YDB 22.4.44, 2022-11-28 {#28-11-2022} ### CVE-2022-28228 {#cve-2022-28228} В сервере YDB обнаружено чтение за пределами допустимого адресного пространства. Злоумышленник с помощью специально сконструированного запроса с оператором insert может получить доступ к конфиденциальной информации или вызвать сбой. Ссылка на CVE: [https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-28228](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-28228). + +Обнаружено благодаря Максиму Арнольду. |