PT-2019-1202 · Mysql Server+1 · Mysql Connectors+1

Published

2019-01-16

·

Updated

2024-07-12

·

CVE-2019-2435

CVSS v2.0

8.5

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions MySQL Connectors versions 8.0.13 and prior MySQL Connectors versions 2.1.8 and prior
Description The issue is related to errors in the code of the Connector/Python subcomponent of MySQL Connectors. It allows a remote attacker to gain unauthorized access to protected data using the TLS protocol. Successful attacks require human interaction from a person other than the attacker and can result in unauthorized creation, deletion, or modification access to critical data or all accessible data.
Recommendations For versions 8.0.13 and prior, update to a version later than 8.0.13 to resolve the issue. For versions 2.1.8 and prior, update to a version later than 2.1.8 to resolve the issue. As a temporary workaround, consider restricting access to the TLS protocol until a patch is available.

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

BDU:2019-00295
CVE-2019-2435
GHSA-V5RQ-W2XM-7G5F
MGASA-2020-0345
OPENSUSE-SU-2020:0409-1
OPENSUSE-SU-2020:0430-1
OPENSUSE-SU-2020_0409-1
OPENSUSE-SU-2024:11240-1
OPENSUSE-SU-2024:14149-1

Affected Products

Mysql Connectors
Suse