CVE-2024-53257 - CVE House
Back to Database
Status published Medium CVE-2024-53257

Vitess allows HTML injection in /debug/querylogz & /debug/env

Vulnerability Description

Vitess is a database clustering system for horizontal scaling of MySQL. The /debug/querylogz and /debug/env pages for vtgate and vttablet do not properly escape user input. The result is that queries executed by Vitess can write HTML into the monitoring page at will. These pages are rendered using text/template instead of rendering with a proper HTML templating engine. This vulnerability is fixed in 21.0.1, 20.0.4, and 19.0.8.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-53257

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

vitess
Vulnerable Versions:
>= 0.21.0-rc1, < 21.0.1, >= 0.20.0-rc1, < 20.0.4, < 19.0.8

Timeline

Official Publish: December 3rd, 2024
Last Modified: December 3rd, 2024
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N

Weaknesses (CWE)