PT-2017-3926 · Percona+2 · Percona Xtradb Cluster+3

Publicado

2017-12-11

·

Atualizado

2023-12-29

·

CVE-2017-15365

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MariaDB versions prior to 10.1.30 MariaDB versions 10.2.x prior to 10.2.10 Percona XtraDB Cluster versions prior to 5.6.37-26.21-3 Percona XtraDB Cluster versions 5.7.x prior to 5.7.19-29.22-3
Description The issue is related to incorrect ordering of DDL replication and ACL checking in the sql/event data objects.cc file, allowing remote authenticated users with SQL access to bypass intended access restrictions. This can lead to replication of data definition language (DDL) statements to cluster nodes. The vulnerability may allow an attacker to gain unauthorized access to confidential data, cause a denial of service, and impact data integrity.
Recommendations For MariaDB versions prior to 10.1.30, update to version 10.1.30 or later. For MariaDB versions 10.2.x prior to 10.2.10, update to version 10.2.10 or later. For Percona XtraDB Cluster versions prior to 5.6.37-26.21-3, update to version 5.6.37-26.21-3 or later. For Percona XtraDB Cluster versions 5.7.x prior to 5.7.19-29.22-3, update to version 5.7.19-29.22-3 or later.

Correção

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2018-1014
ALT-PU-2018-2387
ALT-PU-2018-2496
BDU:2020-00680
CVE-2017-15365
DSA-4341-1
MGASA-2018-0088
RHSA-2019:1258
SUSE-RU-2023:3956-1
SUSE-RU-2023:4991-1
SUSE-SU-2018:1853-1
SUSE-SU-2019:1441-1

Produtos afetados

Alt Linux
Mariadb
Mariadb Server
Percona Xtradb Cluster