Apache · Apache Shardingsphere-Proxy · CVE-2022-45347
**Name of the Vulnerable Software and Affected Versions**
Apache ShardingSphere-Proxy versions prior to 5.3.0
**Description**
The issue arises when Apache ShardingSphere-Proxy is used with MySQL as the database backend. In versions prior to 5.3.0, the database session is not properly cleaned up after a client authentication failure. This allows an attacker to execute normal commands by constructing a special MySQL client.
**Recommendations**
For versions prior to 5.3.0, update to Apache ShardingSphere 5.3.0 to resolve the issue. As a temporary workaround, consider restricting access to the MySQL database backend to minimize the risk of exploitation.