Oracle · Mysql Client · CVE-2021-2010
Name of the Vulnerable Software and Affected Versions:
MySQL Client versions 5.6.50 and prior
MySQL Client versions 5.7.32 and prior
MySQL Client versions 8.0.22 and prior
Description:
The issue is related to insufficient access control in the C API component of the MySQL Client. It can be exploited by a remote attacker to cause a denial of service using the MySQL protocol. A successful attack can result in unauthorized access to update, insert, or delete some MySQL Client accessible data, as well as cause a partial denial of service of MySQL Client.
Recommendations:
For versions 5.6.50 and prior, update to a version later than 5.6.50 to resolve the issue.
For versions 5.7.32 and prior, update to a version later than 5.7.32 to resolve the issue.
For versions 8.0.22 and prior, update to a version later than 8.0.22 to resolve the issue.
As a temporary workaround, consider restricting network access to the MySQL Client to minimize the risk of exploitation.