PT-2023-2668 · Mysql Server+2 · Mysql Connectors+2

Publicado

2023-04-18

·

Atualizado

2024-08-28

·

CVE-2023-21971

CVSS v2.0

5.8

Média

VetorAV:N/AC:H/Au:M/C:P/I:P/A:C
Name of the Vulnerable Software and Affected Versions MySQL Connectors versions 8.0.32 and prior
Description The vulnerability exists due to insufficient input validation in the Connector/J component of the MySQL Connectors product. A difficult to exploit vulnerability allows a high privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks require human interaction from a person other than the attacker and can result in unauthorized ability to cause a hang or frequently repeatable crash of MySQL Connectors, as well as unauthorized update, insert, or delete access to some of MySQL Connectors accessible data and unauthorized read access to a subset of MySQL Connectors accessible data.
Recommendations For versions 8.0.32 and prior, update to a version that contains a fix for this vulnerability. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-02508
CVE-2023-21971
OPENSUSE-SU-2023_2979-1
OPENSUSE-SU-2024:12927-1
SUSE-SU-2023:2241-1
SUSE-SU-2023:2979-1

Produtos afetados

Mysql Connectors
Red Os
Suse