Oracle · Mysql Server · CVE-2022-21592
**Name of the Vulnerable Software and Affected Versions**
MySQL Server versions 5.7.39 and prior
MySQL Server versions 8.0.29 and prior
**Description**
The issue exists due to insufficient input validation in the MySQL Server's encryption component. This allows a remote attacker to disclose protected information. Successful attacks can result in unauthorized read access to a subset of MySQL Server accessible data.
**Recommendations**
For MySQL Server versions 5.7.39 and prior, update to a version later than 5.7.39 to resolve the issue.
For MySQL Server versions 8.0.29 and prior, update to a version later than 8.0.29 to resolve the issue.
As a temporary workaround, consider restricting network access to the MySQL Server to minimize the risk of exploitation.