PT-2021-3622 · Percona+9 · Percona Server+10

Sergei Golubchik

·

Published

2021-02-22

·

Updated

2025-09-29

·

CVE-2021-27928

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions MariaDB versions 10.2 through 10.2.37 MariaDB versions 10.3 through 10.3.28 MariaDB versions 10.4 through 10.4.18 MariaDB versions 10.5 through 10.5.9 Percona Server through 2021-03-03 wsrep patch through 2021-03-03 for MySQL
Description The issue is related to a remote code execution problem in MariaDB, where an untrusted search path leads to eval injection. This allows a database SUPER user to execute OS commands after modifying wsrep provider and wsrep notify cmd. The vulnerability is due to the lack of input validation.
Recommendations For MariaDB versions 10.2 through 10.2.37, update to version 10.2.37 or later. For MariaDB versions 10.3 through 10.3.28, update to version 10.3.28 or later. For MariaDB versions 10.4 through 10.4.18, update to version 10.4.18 or later. For MariaDB versions 10.5 through 10.5.9, update to version 10.5.9 or later. For Percona Server through 2021-03-03, update to a version later than 2021-03-03. For wsrep patch through 2021-03-03 for MySQL, update to a version later than 2021-03-03. As a temporary workaround, consider restricting access to the wsrep provider and wsrep notify cmd variables to minimize the risk of exploitation.

Exploit

Fix

RCE

OS Command Injection

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2021:1242
ALSA-2021_1242
ALSA-2021_3590
ALSA-2022_1065
ALSA-2022_1556
ALSA-2022_1557
ALSA-2022_5326
ALSA-2022_5826
ALSA-2022_5948
ALSA-2022_6443
ALSA-2022_6590
ALSA-2022_7106
ALSA-2022_7119
ALSA-2022_7314
ALSA-2022_7793
ALSA-2022_8291
ALSA-2023_5763
ALSA-2023_6745
ALSA-2025_16880
ALT-PU-2021-2179
ALT-PU-2021-2222
ALT-PU-2021-2236
BDU:2021-03770
BIT-MARIADB-2021-27928
BIT-MARIADB-MIN-2021-27928
BIT-MYSQL-CLIENT-2021-27928
CESA-2021_1242
CVE-2021-27928
DLA-2605-1
ELSA-2021-1242
OESA-2021-1250
OPENSUSE-SU-2021:2605-1
OPENSUSE-SU-2021:2616-1
OPENSUSE-SU-2021:2617-1
OPENSUSE-SU-2021_2605-1
OPENSUSE-SU-2021_2616-1
OPENSUSE-SU-2021_2617-1
OPENSUSE-SU-2024:11648-1
RHSA-2021:1039
RHSA-2021:1240
RHSA-2021:1241
RHSA-2021:1242
RHSA-2021:2040
RHSA-2021_1242
RLSA-2021:1242
RLSA-2021_1242
ROSA-SA-2023-2252
SUSE-RU-2023:3956-1
SUSE-RU-2023:4991-1
SUSE-SU-2021:2605-1
SUSE-SU-2021:2616-1
SUSE-SU-2021:2617-1
SUSE-SU-2021:2634-1
SUSE-SU-2021_2605-1
SUSE-SU-2021_2616-1
SUSE-SU-2021_2617-1
SUSE-SU-2021_2634-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Mariadb
Mariadb Server
Mysql Server
Percona Server
Red Hat
Rocky Linux
Suse